Skip to content

Security: picminjs/picmin

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.x.x

Reporting a Vulnerability

If you discover a security vulnerability in picmin, please report it responsibly:

  1. Do NOT open a public GitHub issue
  2. Email the maintainer directly or use GitHub's private vulnerability reporting
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

Response Timeline

  • Initial response: Within 48 hours
  • Status update: Within 7 days
  • Fix release: Depends on severity
    • Critical: Within 24-48 hours
    • High: Within 7 days
    • Medium/Low: Next regular release

Security Best Practices

When using picmin:

  1. Keep updated: Always use the latest version
  2. Validate inputs: Ensure image sources are trusted
  3. Check outputs: Verify compressed files before distribution
  4. Use in isolation: Consider running in containers for untrusted inputs

Dependencies

picmin relies on these dependencies which have their own security policies:

We actively monitor for vulnerabilities in our dependencies using npm audit.

There aren’t any published security advisories