Security fixes are applied to the latest published versions of docora and create-docora on npm.
| Package | Supported |
|---|---|
docora (latest) |
Yes |
create-docora (latest) |
Yes |
| Older published versions | Best effort |
Please do not open a public GitHub issue for security reports.
Report privately through one of these channels:
- GitHub private vulnerability reporting
- Email hello@staticmania.com with the subject
Docora security report
Include as much detail as you can:
- A description of the issue and its impact
- Steps to reproduce, or a proof of concept
- Affected package names and versions
- Any suggested fix, if you have one
- We will acknowledge the report as soon as we can.
- We will investigate and keep you informed of the status.
- If the report is confirmed, we will prepare a fix and coordinate disclosure.
- Please give us a reasonable window to ship a fix before discussing the issue publicly.
Thank you for helping keep Docora and its users safe.