Skip to content

Security: Yvancg/validators

SECURITY.md

Security Policy

Supported Versions

The Validators project follows a rolling-release model.
Only the latest main branch is actively maintained for bug and security fixes.

Version Supported
main
< main

Reporting a Vulnerability

If you discover a security issue or suspect a potential vulnerability:

  1. Do not open a public issue.
    Please report it privately via email at security@y-consulting.us or through GitHub Security Advisories.

  2. Include the following information:

    • A clear description of the issue
    • Steps to reproduce, if applicable
    • Impact or potential exploit scenario
    • Suggested mitigation or fix (optional)
  3. You will receive an acknowledgment within 72 hours.
    Once verified, we will:

    • Reproduce and confirm the issue
    • Work on a fix in a private branch
    • Credit responsible disclosure in release notes (unless anonymity requested)

Disclosure Policy

  • Coordinated disclosure preferred.
  • Fixes are released publicly once validated and merged into main.
  • Proof-of-concept or exploit details are not published until a patch is available.

Scope

This policy applies to all modules in the Validators repository:

  • is-card-safe
  • is-email-safe
  • is-iban-safe
  • is-ip-safe
  • is-json-safe
  • is-password-safe
  • is-phone-e164
  • is-url-safe
  • is-us-tin-safe
  • is-vat-safe
  • etc

© 2025 Y Consulting LLC — Validators Project

There aren’t any published security advisories