If you discover a security vulnerability in AuthPool, please do not open a public GitHub issue.
Instead, email ashbhati26@gmail.com with:
- A description of the vulnerability
- Steps to reproduce it
- The potential impact
You can expect an initial response within 72 hours. Once confirmed, a fix will be prioritized and a security advisory published after a patch is released.
| Version | Supported |
|---|---|
| 3.x | ✅ |
| < 3.0 | ❌ |
This policy covers the authpool npm package itself (this repository). It does not cover vulnerabilities in third-party dependencies — please report those upstream, though we'll gladly take a PR that bumps a vulnerable dependency here.