svelte-docsmith is pre-1.0 and moves quickly. Security fixes are released against the latest published version only. Please make sure you're on the current release before reporting.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, use GitHub's private vulnerability reporting: go to the repository's Security tab and click Report a vulnerability. This opens a private advisory visible only to the maintainers.
When reporting, please include as much of the following as you can:
- A description of the vulnerability and its impact.
- Steps to reproduce, or a proof of concept.
- Affected version(s) and environment.
- Any suggested mitigation, if you have one.
- We'll acknowledge your report within a few days.
- We'll keep you updated as we investigate and work on a fix.
- Once a fix is released, we're happy to credit you in the advisory unless you'd prefer to remain anonymous.
Thank you for helping keep svelte-docsmith and its users safe.