We release patches for security vulnerabilities for the following versions:
| Version | Supported |
|---|---|
| 1.x.x | ✅ |
| < 1.0 | ❌ |
If you discover a security vulnerability within this package, please send an email to the maintainer. All security vulnerabilities will be promptly addressed.
Please do not report security vulnerabilities through public GitHub issues.
When reporting a vulnerability, please include:
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact of the vulnerability
- Suggested fix (if you have one)
- We will acknowledge receipt of your vulnerability report within 48 hours
- We will provide a detailed response within 7 days
- We will work on a fix and keep you updated on progress
- Once fixed, we will release a patch and publicly disclose the vulnerability
When using this package:
- Keep dependencies updated - Always use the latest version
- Validate user input - Never trust user input in route parameters
- Use HTTPS - Always use secure connections in production
- Sanitize URLs - Be careful with user-generated URLs
We follow a responsible disclosure policy:
- Security issues are fixed privately
- A patch release is prepared
- The vulnerability is publicly disclosed after the patch is released
- Credit is given to the reporter (if desired)
Thank you for helping keep Inertia Route Helper secure! 🔒