Skip to content

Security: TidyFactor/HTML

Security

.github/SECURITY.md

Security Policy

Supported Versions

We actively provide security patches and updates for the following versions:

Version Supported
1.1.x
1.0.x
< 1.0

Reporting a Vulnerability

We take the security of TidyFactor Styler and its associated workflows seriously. Please do not report security vulnerabilities via public GitHub issues or discussions.

  1. Private Reporting:

    • Open a private security report through GitHub Security Advisories.
    • Alternatively, email security@tidyfactor.com or hello@tidyfactor.com.
  2. Details to Include:

    • Description of the vulnerability and attack vector.
    • Exact steps or script to reproduce the issue.
    • Potential impact on users or downstream implementations.
  3. Response SLA:

    • Acknowledgement within 48 hours.
    • Coordinated disclosure and patch release in accordance with standard SemVer rules.

There aren't any published security advisories