Skip to content

Security: ngandu-dev/flexpay

Security

SECURITY.md

Security policy

Reporting a vulnerability

Do not report security vulnerabilities in public issues, discussions, or pull requests.

Email bernard@ngandu.dev with:

  • the affected package and version;
  • a description of the vulnerability and its impact;
  • reproduction steps or a proof of concept;
  • any suggested mitigation, if available.

You should receive an acknowledgement within five business days. We will coordinate disclosure and remediation with you. Please allow a reasonable amount of time for a fix before publishing details.

Only supported releases are eligible for security fixes. Support information is documented in the package README or release notes.

There aren't any published security advisories