Skip to content

Security: andreadito/pipequery

SECURITY.md

Security Policy

Supported Versions

Only the latest minor release of each package receives security fixes:

Package Supported
@andreadito/pipequery-lang latest 1.9.x
@andreadito/pq latest 0.10.x

Reporting a Vulnerability

Please report security vulnerabilities privately through GitHub's private vulnerability reporting. Do not open a public issue, discussion, or pull request.

Include a description of the issue and its impact, steps to reproduce (a minimal proof-of-concept is ideal), the affected version(s), and any suggested mitigation if known.

You can expect an initial acknowledgement within 5 business days. We'll keep you updated as we triage and develop a fix, then coordinate disclosure once the fix is released — typically via a GitHub Security Advisory that credits the reporter (unless you prefer to remain anonymous).

There aren't any published security advisories