# Security Policy ## Supported Versions Security fixes are handled on a best-effort basis for: - the latest published npm release of `skvlt` - the current `main` branch in this repository Older versions may receive guidance, but they should not be assumed to receive patches. ## Reporting a Vulnerability Please do not open public GitHub issues or pull requests for suspected vulnerabilities. Preferred reporting path: 1. Use GitHub Private Vulnerability Reporting for this repository if it is available. 2. If private vulnerability reporting is not available, use the private maintainer contact methods listed at [xi-xu.me/contact](https://xi-xu.me/#contact) and clearly label the message as a security report for `skills-vault`. Please include: - a description of the issue and impact - affected versions or commit range, if known - reproduction steps or a proof of concept - any suggested remediation, if you already have one ## Response Expectations This project is maintained on a best-effort basis, but the goal is to: - acknowledge new reports within 5 business days - keep the reporter updated on triage status when material progress is made - coordinate public disclosure after a fix or mitigation is available ## Scope This policy covers vulnerabilities in this repository, including: - CLI command behavior - manifest parsing and install planning - release and packaging configuration in this repository If a report only affects an upstream dependency or the external Skills CLI itself, it may need to be reported upstream as well. ## Security Practices in This Repo This repository already uses several baseline security controls, including dependency review automation and locked Bun installs in CI. Additional repository settings such as branch protection, MFA for privileged contributors, and GitHub private vulnerability reporting should stay enabled wherever available.