Skip to content

Security: bghcore/formosaic

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.x
< 1.0

Reporting a Vulnerability

We take security issues in all @formosaic/* packages seriously.

Please do not report security vulnerabilities through public GitHub issues.

Instead, please report them using GitHub Security Advisories. This allows us to assess the issue and work on a fix privately before public disclosure.

What to Include

  • A description of the vulnerability
  • Steps to reproduce the issue
  • Affected package(s) and version(s)
  • Any potential impact you've identified

Response Timeline

  • Acknowledgment: Within 48 hours of your report
  • Initial assessment: Within 5 business days
  • Fix timeline: Depends on severity; critical issues are prioritized for immediate patching

Scope

This policy applies to all packages in the Formosaic monorepo:

  • @formosaic/core
  • @formosaic/fluent
  • @formosaic/mui
  • @formosaic/headless
  • @formosaic/antd
  • @formosaic/chakra
  • @formosaic/mantine
  • @formosaic/atlaskit
  • @formosaic/base-web
  • @formosaic/heroui
  • @formosaic/radix
  • @formosaic/react-aria

There aren’t any published security advisories