| Version | Supported |
|---|---|
| 1.x.x | ✅ |
If you discover a security vulnerability in picmin, please report it responsibly:
- Do NOT open a public GitHub issue
- Email the maintainer directly or use GitHub's private vulnerability reporting
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Initial response: Within 48 hours
- Status update: Within 7 days
- Fix release: Depends on severity
- Critical: Within 24-48 hours
- High: Within 7 days
- Medium/Low: Next regular release
When using picmin:
- Keep updated: Always use the latest version
- Validate inputs: Ensure image sources are trusted
- Check outputs: Verify compressed files before distribution
- Use in isolation: Consider running in containers for untrusted inputs
picmin relies on these dependencies which have their own security policies:
We actively monitor for vulnerabilities in our dependencies using npm audit.