Skip to content

Security: skeptrunedev/sherp

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x

Reporting a Vulnerability

We take security seriously. If you discover a security vulnerability in Sherp, please report it responsibly.

How to Report

  1. Do not open a public GitHub issue for security vulnerabilities
  2. Email the maintainers directly or use GitHub's private vulnerability reporting feature
  3. Include as much detail as possible:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Any suggested fixes (optional)

What to Expect

  • We will acknowledge receipt of your report within 48 hours
  • We will provide an initial assessment within 7 days
  • We will work with you to understand and resolve the issue
  • Once fixed, we will publicly acknowledge your contribution (unless you prefer to remain anonymous)

Scope

This security policy applies to:

  • @skeptrunedev/sherp-cli
  • @skeptrunedev/sherp-astro

Out of Scope

  • Vulnerabilities in dependencies (please report these to the respective projects)
  • Issues in user-created presentation content
  • Social engineering attacks

Security Best Practices for Users

When using Sherp:

  • Keep your dependencies up to date
  • Only use trusted MDX components in your presentations
  • Review any custom JavaScript before including it in your presentations
  • When deploying, follow your hosting provider's security recommendations

Thank you for helping keep Sherp and its users safe!

There aren’t any published security advisories