Please practice responsible disclosure. Report a security issue to us privately, and give us time to fix it before you tell anyone else.
Do not report security issues in public issues, discussions or pull requests.
Report them in one of two ways:
Include:
- The affected file, package or URL.
- The steps to reproduce the issue.
- The impact you expect.
- We confirm receipt within 3 business days.
- We tell you if we accept the issue, and we keep you informed while we fix it.
- We tell you when we release a fix. With your permission, we credit you in the release.
This policy covers:
- The content of this repository.
- The
@scrums/*npm packages built frompackages/. - The documentation at scrums.com/docs.
For the Scrums.com platform, use the same channels.
We fix security issues in the latest release of each package. Packages at 0.x can change between minor versions.