Skip to content

Security: iSimplifyMe/isimplifyme-ui

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Email ai@isimplifyme.com with SECURITY in the subject line. Please include the affected repository, the version or commit, what an attacker could actually do with the issue, and the smallest reproduction you can share.

Do not open a public issue for a vulnerability. If you have already opened one, email us and we will coordinate from there.

What to expect

We acknowledge reports on a best-effort basis, typically within five business days. These repositories are maintained on a monthly review cadence, so please allow time for a substantive response beyond the initial acknowledgement.

We will tell you whether we consider the report in scope, and we will credit you in the fix commit or release notes unless you would rather we did not.

Scope

In scope: code in this organization's public repositories, and the published aeo-scan package on npm.

Out of scope: findings against isimplifyme.com or client sites that do not originate in this published code; scanner output presented without a demonstrated impact; and defects in third-party dependencies, which should be reported upstream.

There aren't any published security advisories