We aim to support the latest published version of the project. Security updates are applied to the current major version only.
Please ensure you are using the most recent versions of the Spectre Arsenal packages. Older releases may not receive security fixes.
If you discover a security vulnerability, please DO NOT open a public issue. Security issues should be reported privately to protect users.
Preferred method: Use GitHub Security Advisories to privately report vulnerabilities on the specific repository.
Alternative methods:
- Direct message maintainers through GitHub
- Email the maintainers if provided in the repository
Please provide as much detail as possible to help us reproduce and assess impact:
- Description of the vulnerability and potential impact
- Steps to reproduce or proof-of-concept code
- Affected versions (if known)
- Potential attack scenarios
- Suggested mitigation (if you have ideas)
- Acknowledgment: We will acknowledge receipt within 48 hours
- Assessment: We will investigate and provide an initial assessment within 5 business days
- Updates: We will keep you informed of the fix status throughout the process
- Resolution: We will work on a fix and coordinate disclosure timing with you
- Credit: We will credit you in the security advisory (unless you prefer to remain anonymous)
We appreciate responsible disclosure and will work with you to:
- Understand the scope and severity of the issue
- Develop and test a fix
- Coordinate public disclosure timing
- Credit your contribution (if desired)
Please allow us reasonable time to address the issue before public disclosure.
When using the Spectre Arsenal:
- Keep dependencies updated to the latest versions.
- Monitor dependencies for known vulnerabilities (
npm audit). - Use HTTPS for all production sites.
- Sanitize user input when using classes or components dynamically.
- Follow framework security best practices (WordPress, Astro, React, etc.).
For security-related questions that aren't vulnerabilities:
- Open a GitHub Discussion on the repository
- Tag maintainers in relevant issues
Thank you for helping keep the Spectre community safe!