The latest minor release of @bonyanoss/bonyan-api is supported with security updates. Older versions are best-effort only — please upgrade when a fix is published.
| Version | Supported |
|---|---|
| 1.x | ✅ |
| < 1.0 | ❌ |
Please do not open a public GitHub issue for security reports.
Instead, send a private report through one of these channels:
- GitHub Security Advisories — https://github.com/BonyanOSS/bonyan-sdk-js/security/advisories/new (preferred).
- Email the maintainers via the address listed in the BonyanOSS organisation profile.
When reporting, please include:
- A clear description of the vulnerability and its impact.
- Steps to reproduce (a minimal code snippet is ideal).
- The SDK version, Node.js / browser runtime, and any other relevant environment details.
- Within 72 hours — we acknowledge receipt of your report.
- Within 7 days — we provide an initial assessment and an expected fix timeline.
- Coordinated disclosure — once a fix is ready, we publish a release and a GitHub Security Advisory with credit to the reporter (unless anonymity is requested).
Thank you for helping keep @bonyanoss/bonyan-api and its users safe.