Skip to content

Security: newjersey/njwds

SECURITY.md

Security Policy

Supported Versions

Security updates are provided for the latest minor release of the current major version of this design system.

Version Supported
2.9.x ✅ Yes
< 2.9 ❌ No

Consumers are encouraged to stay up to date with the latest release to ensure they receive security fixes and dependency updates.


Reporting a Vulnerability

If you believe you have found a security vulnerability in this design system, please do not open a public GitHub issue.

Instead, report the to repositiry administrators.

When reporting a vulnerability, please include:

  • A description of the issue and its potential impact
  • Steps to reproduce the vulnerability, if applicable
  • Any relevant screenshots, logs, or proof-of-concept code

What to expect

  • You should receive an acknowledgment within a reasonable timeframe.
  • The team will evaluate the report and may request additional information.
  • If the vulnerability is confirmed, we will work to address it and release a fix in a supported version.
  • If the report is declined, we will provide a brief explanation where possible.

We appreciate responsible disclosure and efforts to help keep this project and its consumers secure.


Dependency Security

This project uses automated tooling (such as npm audit) to monitor dependencies for known vulnerabilities. Critical vulnerabilities are treated as release-blocking issues.


Thank you for helping improve the security of this project.

There aren’t any published security advisories