Skip to content

Security: jcatama/markdown-redactor

Security

SECURITY.md

Security Policy

Supported versions

The latest minor release line is supported for security fixes.

Reporting a vulnerability

If you discover a security issue:

  1. Do not open a public issue.
  2. Send a private report with:
    • impact summary
    • reproduction steps
    • affected version(s)
    • suggested remediation (if available)
  3. Include proof-of-concept data that is safe and sanitized.

Response expectations

  • Initial acknowledgment target: 3 business days
  • Triage target: 7 business days
  • Fix timeline depends on severity and exploitability

Scope notes

This library performs best-effort pattern redaction and is not a full DLP platform. Use defense in depth in production:

  • access controls
  • data classification
  • policy enforcement
  • monitoring and incident response

There aren’t any published security advisories