The B.C. Web Style Guide Checker is currently a pilot. Security updates are provided for the current preview release.
| Version | Supported |
|---|---|
| 1.3.2 | ✅ |
| 1.3.1 and earlier | ❌ |
People using an earlier preview should update to the current release before continuing.
Update this table whenever the minimum supported preview version changes.
Use GitHub private vulnerability reporting to report a suspected vulnerability.
Do not include vulnerability details in a public issue, discussion or pull request.
Include:
- The affected extension version
- The browser and operating system
- A clear description of the issue and its potential impact
- Minimal steps to reproduce it safely
- Any suggested mitigation
- Whether you believe the issue is being actively exploited
Use synthetic or redacted examples. Do not include passwords, cookies, sign-in tokens, personal information, confidential page content or information from systems you are not authorized to access.
If private vulnerability reporting is unavailable, open a public issue asking the maintainers to restore the private reporting channel. Do not include details of the vulnerability.
The maintainers aim to acknowledge a report within 5 business days.
After an initial assessment, the maintainers will:
- Confirm whether the report is being investigated
- Request more information when needed
- Provide updates when the status materially changes
- Coordinate remediation and disclosure when a vulnerability is confirmed
- Explain the decision when a report is closed without a security change, when practical
Response and remediation times depend on severity, complexity and the availability of a safe correction.
Please allow the maintainers reasonable time to investigate and address a confirmed vulnerability before publishing technical details.
When public disclosure is appropriate, the timing and content will be coordinated with the reporter where possible. The reporter may be credited unless they prefer to remain anonymous.
Use a regular GitHub issue for product defects, inaccurate findings and feature requests that do not present a security risk.