Security fixes are provided for the latest released version of openspec-viewer.
Please do not disclose security vulnerabilities in a public issue.
Use GitHub's Report a vulnerability option on the repository's Security tab to send the maintainers a private report. Include:
- The affected version or commit
- Steps to reproduce the issue
- The expected and actual behavior
- The potential impact
- Any suggested mitigation, if known
You should receive an acknowledgment within seven days. We will coordinate a fix and disclosure timeline with you after validating the report.
If private vulnerability reporting is unavailable, contact the maintainer through the GitHub profile linked from the repository and request a private reporting channel without sharing vulnerability details publicly.