Skip to content

Security: JairusSW/json-ty

Security

SECURITY.md

Security Policy

Supported versions

json-ty is currently an early 0.0.0 preview installed from GitHub. Security fixes are applied to the latest main revision; older commits are not supported as separate release lines.

Reporting a vulnerability

Please do not open a public issue for a vulnerability that could put users or their data at risk.

Email me@jairus.dev with:

  • a minimal reproduction or malformed input;
  • affected commit and Node version;
  • expected and observed behavior;
  • potential impact;
  • any suggested fix or mitigation.

Reports will be acknowledged as soon as practical and handled privately until a fix or coordinated disclosure plan is ready. Credit will be given with the reporter's permission.

Memory-safety, stale-view, allocator, parser-boundary, generated-code injection, and malicious-schema issues are especially valuable to report.

There aren't any published security advisories