artgraph is pre-1.0. Only the latest published minor release line (the
newest 0.x minor on npm) receives
security fixes. Because the project is pre-1.0, the public API may change
between minor releases, and previous minor lines are not maintained.
| Version | Supported |
|---|---|
Latest 0.x minor |
✅ |
| Older release lines | ❌ |
Please do not file a public GitHub issue for security reports.
Report vulnerabilities privately through GitHub's Private Vulnerability Reporting:
- Open the Security tab of this repository.
- Click Report a vulnerability.
- Describe the issue, steps to reproduce, affected versions, and — if you have one — a suggested mitigation.
artgraph is maintained on a best-effort basis. For a valid report, we will:
- Acknowledge receipt within 7 days.
- Triage and confirm (or reject) the report within 14 days when feasible.
- Coordinate disclosure with the reporter and publish a fix as a patch release on the latest minor line.
No bug bounty program is offered.