Skip to content

Security: Cedric-ruiu/stylelint-config

SECURITY.md

Security Policy

Supported versions

Version Supported
2.x
1.x

Reporting a vulnerability

Please report security issues privately through GitHub Security Advisories, not as a public issue.

Expect an acknowledgement within a few days. This is a single-maintainer package, so please allow reasonable time for a fix before disclosing publicly.

Scope

This package is a Stylelint configuration — it ships no executable code beyond a plain config object, and it runs only in a developer's or CI environment, never in production. The realistic attack surface is its dependency tree. Dependency updates are automated via Dependabot, and releases are published to npm with provenance attestation.

There aren't any published security advisories