Before the first public release, security fixes are applied to the default branch. After publication, only the latest released version of @polishedapps/doc-splitter is supported.
Do not report security vulnerabilities in a public issue.
Use GitHub private vulnerability reporting to send a private report to the maintainers.
If GitHub private vulnerability reporting is unavailable, email security@polishedapps.com. This address is monitored by PolishedApps LLC.
Include:
- the affected package version;
- the Node.js version and operating system;
- a clear description of the vulnerability and its potential impact;
- minimal reproduction steps or a proof of concept; and
- any suggested mitigation, if known.
Do not attach confidential or personal documents. Use a minimal generated or redacted test file when a document is required to demonstrate the issue.