| Version | Supported |
|---|---|
| 1.x | Yes |
| < 1.0 | No |
If you discover a security vulnerability in Next-Unicorn, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
Instead, please email security@nebutra.com or use GitHub Security Advisories to report the vulnerability privately.
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgement: within 48 hours
- Initial assessment: within 5 business days
- Fix & disclosure: coordinated with reporter, typically within 30 days
Next-Unicorn takes security seriously:
- Dependency scanning: All current AND recommended dependencies are scanned via the OSV database to prevent "upgrade into a vulnerability" scenarios
- No secrets in code: All external clients (Context7, OSV, npm registry, GitHub API) are injected via interfaces — no credentials are hardcoded
- License compliance: License allowlist filtering prevents introducing packages with incompatible licenses
- Minimal dependencies: Only 2 runtime dependencies (
zod,semver) to minimize attack surface - npm provenance: Packages are published with Sigstore provenance for supply chain verification
- Strict TypeScript: Full strict mode with no
anyescapes
This policy covers the @nebutra/next-unicorn-skill npm package and the Nebutra/Next-Unicorn-Skill GitHub repository.
Vulnerabilities in upstream dependencies should be reported to the respective maintainers.