Skip to content

Security: LTDev-LLC/alpine-component-loader

SECURITY.md

Security policy

Supported versions

Security fixes are provided for the latest published AlpineComponentLoader release. Upgrade to the latest release before reporting behavior that may already have been corrected.

Report a vulnerability

Use GitHub private vulnerability reporting. Do not open a public issue for an unpatched vulnerability.

Include the affected version, impact, reproduction steps, and any suggested mitigation. Reports are handled on a best-effort basis. Maintainers will coordinate validation, remediation, release timing, and public disclosure with the reporter. Please keep details private until a fixed release or an agreed disclosure date is available.

Scope

Reports about template sanitization, SSR, remote loading, generated service workers, the development server, CLI path handling, and dependency supply-chain risks are in scope. Findings that require applications to explicitly disable documented protections are still useful when the resulting risk is surprising or insufficiently documented.

There aren't any published security advisories