Only the latest released version of @vsfedorenko/next-logger receives
security updates.
| Version | Supported |
|---|---|
| latest | ✅ |
| < latest | ❌ |
If you discover a security vulnerability in this project, please report it privately rather than opening a public issue.
Preferred channels (in order):
- GitHub Security Advisories (recommended) — open a private advisory at github.com/vsfedorenko/next-logger/security/advisories/new.
- Email — send details to vadim.fedorenko@… (see the author's GitHub profile for the current address). If possible, encrypt sensitive details using the repository owner's published PGP key.
Please include the following in your report:
- A clear description of the vulnerability and its potential impact.
- Steps to reproduce, including a minimal proof-of-concept if possible.
- The affected version(s).
- Any suggested mitigations or fixes.
- Acknowledgement: within 72 hours.
- Initial assessment: within 7 days.
- Fix or mitigation: target 30 days, depending on severity and complexity.
You will be kept informed of progress, and coordinated disclosure will be arranged once a fix is available. We kindly ask that you do not disclose the vulnerability publicly until a fix has been released.
This policy covers the @vsfedorenko/next-logger package source code in this
repository. Vulnerabilities in dependencies (e.g. consola, next) should be
reported to their respective maintainers.