Skip to content

Security: Nick2bad4u/eslint-plugin-write-good-comments-2

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a vulnerability in this repository, report it privately using one of these channels:

Please do not open public issues for unpatched vulnerabilities.

Include as much detail as possible:

  • Affected version(s)
  • Reproduction steps or proof of concept
  • Security impact
  • Any known mitigations

Supported Versions

Only the latest published release is considered actively supported for security fixes.

Version Supported
Latest
Older

Response Expectations

  • Initial acknowledgment target: within 7 days
  • Triage and remediation timeline: depends on severity and complexity
  • Public disclosure: after a fix is available or a coordinated disclosure date is agreed

Security Best Practices for Users

  • Keep eslint-plugin-write-good-comments-2, ESLint, TypeScript, and dependencies updated.
  • Run linting in CI on trusted code only.
  • Review new rule autofixes before applying at scale.

Credits

Responsible disclosure is appreciated. We can credit reporters in release notes if requested.

There aren’t any published security advisories