Skip to content

Security: npmq/zenums

Security

SECURITY.md

Security Policy

Reporting a vulnerability

If you believe you have found a security issue in zenums, please do not open a public issue first.

Report it privately using one of these channels:

Please include:

  • affected zenums version
  • environment details (node/bun, OS, package manager)
  • a minimal reproduction
  • expected behavior
  • actual behavior
  • any notes about potential impact

Response process

Reports are reviewed on a best-effort basis.

If the issue is confirmed, I will investigate a fix and publish an update when appropriate. I may also add documentation or release notes if that helps users reduce risk.

Please avoid public disclosure until the issue has been reviewed.

Scope

This policy applies to:

  • the published zenums npm package
  • this repository's source code
  • official release artifacts

Issues originating from third-party dependencies may be handled separately depending on severity, available fixes, and package compatibility.

Supported versions

Security fixes, if provided, are generally expected to target the latest published version.

There aren't any published security advisories