Security fixes are made on the latest published release line.
| Version | Supported |
|---|---|
| 0.2.x | Yes |
| 0.1.x | Yes |
Do not open a public issue for a suspected vulnerability.
Email the npm package maintainer at gmorrobel15@gmail.com with the subject
[citewire security]. Include the affected version, impact, reproduction steps,
and any suggested mitigation. Remove secrets, access tokens, personal data, and
third-party content from the report.
You should receive an acknowledgment within five business days. The maintainer will confirm the issue, coordinate a fix and release, and agree on disclosure timing with the reporter. Please allow a reasonable remediation period before public disclosure.
Reports about CiteWire's code, package, release process, and documented configuration are in scope. Vulnerabilities or outages in upstream news and research providers should be reported to those providers unless citewire's use of the provider creates the issue.