| Version | Supported |
|---|---|
| latest | ✅ |
| 5.1.x | ✅ |
| 5.0.x | ❌ |
| 4.0.x | ✅ |
| < 4.0 | ❌ |
If you discover a security vulnerability, please report it responsibly:
- GitHub Security Advisories: Use the "Report a vulnerability" button on the Security tab
- Do NOT open public issues for security vulnerabilities
We aim to acknowledge reports within 48 hours and provide a fix timeline within 7 days.
Vulnerabilities in the following are considered in-scope:
- The Docusaurus website configuration and deployment
- Documentation content and build scripts
- Any authentication or authorization mechanisms (excluding client-side sandbox/mock limitations)
Out-of-scope:
- Third-party dependencies (report to their respective maintainers)
- Client-side mock authentication limitations (e.g., local storage, client-side hashing)
We follow a coordinated disclosure process:
- Reporter submits vulnerability via Security Advisory
- Maintainer acknowledges receipt within 48 hours
- Fix is developed and tested in private
- Fix is released, and the advisory is published publicly