Skip to content

Security: yowainwright/pastoralist

.github/SECURITY.md

Security Policy

Supported Versions

Pastoralist is still iterating toward a stable v1 release. Security fixes are prioritized for the latest published release line.

Version Supported
Latest

Reporting a Vulnerability

Please do not open a public issue for suspected vulnerabilities.

Use GitHub's private vulnerability reporting if it is available for this repository:

https://github.com/yowainwright/pastoralist/security/advisories/new

If private reporting is not available, email the maintainer listed in package.json.

Please include:

  • Affected Pastoralist version or commit SHA
  • Package manager and lockfile type involved, if relevant
  • Minimal reproduction steps or a proof of concept
  • Impact, including whether secrets, dependency updates, or generated PRs are involved

You should receive an acknowledgement within 7 days. Valid reports are triaged privately, fixed on the supported release line, and disclosed through a GitHub Security Advisory when appropriate.

There aren't any published security advisories