Security updates are provided for the latest released version of dotenv-diff.
Please make sure you are on the most recent version before reporting a vulnerability.
If you discover a security vulnerability, please report it responsibly by email to christian.munknissen@gmail.com. Please do not open a public issue, pull request, or discussion for security vulnerabilities, as this may put other users at risk.
When reporting, please include as much detail as possible:
- A description of the vulnerability and its potential impact
- Steps to reproduce or a proof of concept
- The affected version(s)
- Any suggested remediation, if known
We follow a coordinated disclosure process:
- Acknowledgement — We will acknowledge your report within 48 hours.
- Assessment — We will investigate and provide an initial assessment within 7 days, including whether the vulnerability is confirmed and its severity.
- Fix & release — We aim to release a patch for confirmed vulnerabilities within 30 days of the initial report, depending on complexity.
- Public disclosure — Once a fix is available, we will coordinate public disclosure with you. We ask that you keep the vulnerability confidential until a patch has been released, typically no later than 90 days after the report.
We greatly appreciate responsible disclosure and will credit reporters in the release notes unless you prefer to remain anonymous.