Skip to content

Security: sagawrr/react-native-nitro-vision-kit

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in react-native-nitro-vision-kit, please report it responsibly — do not open a public GitHub issue.

Report it privately using GitHub's private vulnerability reporting: go to the Security tab → Report a vulnerability, or open https://github.com/sagawrr/react-native-nitro-vision-kit/security/advisories/new.

Expected Response Time

  • Acknowledgement: within 48 hours.
  • Status update / fix plan: within 7 days.
  • Coordinated public disclosure: after a fix is released, typically within 30–90 days of the initial report (timeline negotiable with the reporter).

Scope

Vulnerabilities in this library's published npm package, its native iOS/Android code, or its GitHub Actions release pipeline are in scope. Issues in upstream dependencies should be reported to their respective maintainers.

Out of Scope

  • Theoretical attacks without a concrete reproduction.
  • Bugs in apps that consume this library but are unrelated to the library itself.

Supported Versions

Only the latest release line receives security fixes.

There aren't any published security advisories