Skip to content

Security: yesiamrocks/cssanimation

SECURITY.md

Security Policy

Thank you for your interest in improving the security of {css}animation. We value and appreciate responsible security disclosures and are committed to resolving any legitimate issues in a timely manner.

Scope

This policy applies only to vulnerabilities found within the codebase of this repository (cssanimation). Issues in third-party dependencies should be reported to their respective maintainers.

Supported Versions

We currently support only the latest version of the library for security updates.

Version Supported
latest ✅ Yes
older ❌ No

Reporting a Vulnerability

If you believe you’ve discovered a security vulnerability, please report it privately by emailing: [email protected]

Please include:

  • A detailed description of the vulnerability
  • Steps to reproduce it or a proof of concept (if possible)
  • Any suggestions for mitigation
  • Your preferred contact method for updates

⚠️ Do not open a public issue to report a vulnerability.

Disclosure Process

We follow a coordinated disclosure process:

  1. You report the issue privately.
  2. We verify and assess the severity.
  3. A fix is prepared and released.
  4. A public disclosure is made, if appropriate.

We aim to acknowledge all reports promptly and, if validated, will work to resolve critical issues as quickly and responsibly as possible.

Credit & Recognition

We’re happy to acknowledge your contribution to securing {css}animation in our changelog and release notes (with your permission).

Thank you for helping make the web a safer place

There aren’t any published security advisories