Skip to content

Security: Abhinav0905/firstseen

Security

SECURITY.md

Security policy

Supported versions

Until 1.0, only the latest published minor release receives security fixes. After 1.0, the current major release and the immediately preceding major release will receive fixes for at least 90 days after a new major release.

Reporting a vulnerability

Please do not open a public issue for a suspected vulnerability.

Use GitHub's private vulnerability reporting for Abhinav0905/firstseen. Include:

  • affected version and environment;
  • minimal reproduction or proof of concept;
  • expected and observed behavior;
  • realistic impact and required attacker capabilities;
  • any suggested mitigation.

You should receive an acknowledgement within 72 hours and an initial assessment within seven days. Timelines for a fix and coordinated disclosure depend on severity and ecosystem impact. Good-faith research that avoids privacy violations, service disruption, and access beyond what is necessary is welcome.

High-value areas

Reports are especially useful when they demonstrate:

  • input text causing command or code execution;
  • path traversal, unsafe symlink behavior, or writing outside requested destinations;
  • credential disclosure in reports, cache, logs, or network requests;
  • a policy bypass that turns a blocking resource into a pass without an allow rule;
  • cache poisoning across resource identities;
  • SARIF or HTML injection that becomes executable in a normal viewer;
  • a registry response being misclassified as authoritative absence.

False-positive or extractor-quality reports that have no security impact belong in normal issues.

Release integrity

Official source releases are published from this GitHub repository. npm releases should use trusted publishing with provenance after the repository owner enables it. Never install a similarly named package based only on an AI recommendation—run FirstSeen on FirstSeen, then verify this repository.

There aren't any published security advisories