Security fixes are applied to the latest published release of each package. We recommend always running the most recent version.
Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.
Instead, use one of these private channels:
- GitHub Security Advisories — open a private report via the "Report a vulnerability" button under the repository's Security tab. This is the preferred method.
- Email — send details to contact@base-framework.dev .
Please include as much of the following as you can:
- The package(s) and version(s) affected.
- A description of the issue and its potential impact.
- Steps to reproduce, or a proof of concept.
- Any suggested mitigation, if you have one.
- We aim to acknowledge your report within 3 business days.
- We'll keep you informed as we investigate and work on a fix.
- Once a fix is released, we're happy to credit you in the advisory unless you prefer to remain anonymous.
We appreciate responsible disclosure and the time you take to help keep base and its users safe.