Skip to content

Security: vsfedorenko/next-logger

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest released version of @vsfedorenko/next-logger receives security updates.

Version Supported
latest ✅
< latest ❌

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it privately rather than opening a public issue.

Preferred channels (in order):

  1. GitHub Security Advisories (recommended) — open a private advisory at github.com/vsfedorenko/next-logger/security/advisories/new.
  2. Email — send details to vadim.fedorenko@… (see the author's GitHub profile for the current address). If possible, encrypt sensitive details using the repository owner's published PGP key.

Please include the following in your report:

  • A clear description of the vulnerability and its potential impact.
  • Steps to reproduce, including a minimal proof-of-concept if possible.
  • The affected version(s).
  • Any suggested mitigations or fixes.

Response timeline

  • Acknowledgement: within 72 hours.
  • Initial assessment: within 7 days.
  • Fix or mitigation: target 30 days, depending on severity and complexity.

You will be kept informed of progress, and coordinated disclosure will be arranged once a fix is available. We kindly ask that you do not disclose the vulnerability publicly until a fix has been released.

Scope

This policy covers the @vsfedorenko/next-logger package source code in this repository. Vulnerabilities in dependencies (e.g. consola, next) should be reported to their respective maintainers.

There aren't any published security advisories