If you discover a security vulnerability, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
Instead, use GitHub's private vulnerability reporting feature on this repository.
Include:
- A description of the vulnerability
- Steps to reproduce it
- The potential impact
- Any suggested fix (if you have one)
We will acknowledge receipt within 48 hours and aim to provide a fix or mitigation plan within 7 days.
| Version | Supported |
|---|---|
| latest | Yes |
This policy covers the system-design-builder application code. Third-party dependencies are managed via npm audit and Dependabot.