Skip to content

Security: bitIO/opencode-provider-balance

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest stable version published to npm is supported with security updates. semantic-release keeps the latest dist-tag current, so always upgrade to the newest release of @bitio/opencode-provider-balance.

Version Supported
Latest stable
Older releases

Reporting a Vulnerability

Do not open a public GitHub issue for an unpatched vulnerability.

  1. Preferred: GitHub Security Advisories — use the Report a vulnerability button on the repository's Security tab. It creates a private advisory visible only to the maintainers.
  2. Fallback: email opensource@bitio.dev.

Include in your report:

  • Affected version(s)
  • Steps to reproduce or a proof of concept
  • Impact and a severity estimate

Disclosure Policy

We acknowledge reports promptly and coordinate with reporters on disclosure. Please do not publish details of an unpatched vulnerability — give us a reasonable window to release a fix before going public.

There aren't any published security advisories