Security fixes are provided for the latest stable Messagevisor release line. Upgrade to the latest release before reporting an issue that may already have been fixed.
Please do not open a public issue for a suspected vulnerability.
Use GitHub's private vulnerability reporting form to submit a report. Include the affected package and version, impact, reproduction steps, and any suggested mitigation.
You should receive an initial response within seven days. We will coordinate investigation, remediation, release timing, and disclosure with the reporter.
This policy covers Messagevisor packages and generated artifacts. Vulnerabilities in an application's hosting, CDN, repository permissions, or deployment configuration should be reported to that application's owner