Polyconv is pre-1.0. Security fixes are provided for the latest minor release, the latest code on develop, and production releases from main.
| Version | Supported |
|---|---|
main |
Yes |
develop |
Yes |
0.1.x |
Yes |
Please do not report security vulnerabilities in public issues.
Use one of these channels:
- Open a private GitHub Security Advisory:
- If advisory flow is unavailable, open an issue with minimal details and ask for a private contact channel.
Please include:
- a clear description of the issue
- impact and affected components
- reproduction steps or proof of concept
- suggested mitigation (if available)
We aim to acknowledge reports within 7 days. Fix timelines depend on severity, exploitability, and affected package scope.
Security fixes should land in develop first, then be promoted to main for production release when publishing is required.
Security reports may cover any package in this repository, including @polyconv/cli, @polyconv/core, and @polyconv/json.