| Version | Supported |
|---|---|
| 0.x | ✅ |
@m8t-jacob/validate has zero runtime dependencies and performs no I/O, so
its attack surface is limited to the validation logic itself (e.g. a
malicious input that causes excessive CPU usage or a false-positive/negative
result).
If you discover a security vulnerability, please do not open a public issue. Instead, report it privately via GitHub Security Advisories for this repository.
Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce (a minimal code sample is ideal)
- The package version affected
We aim to acknowledge reports within 5 business days and to release a fix as soon as reasonably possible.