| Version | Supported |
|---|---|
| 0.1.x | ✅ |
Please report security issues privately via GitHub Security Advisories (the "Report a vulnerability" button on the Security tab).
Do not open public issues for security reports.
- Acknowledgement target: 7 days
- Fix or mitigation target: 90 days from acknowledgement
- Coordinated public disclosure once a patched release is available
In scope:
- Determinism / correctness of
scripts/calc.jsand the per-skill calculators - Integrity of canton data files under
data/cantons/and skill-leveldata/ - Validators (
scripts/validate-uid.js,validate-iban.js,validate-qr-reference.js,validate-invoice.js) - Template content that could mislead users about Swiss legal/fiscal obligations
Out of scope:
- Issues in upstream dependencies — please report those upstream first
- Use of templates as legal advice (templates are illustrative, not advice)
- Numeric values flagged with
_disclaimer— these are sample/illustrative