Skip to content

Security: dyka3773/mvn-tree-visualizer

Security

.github/SECURITY.md

Security Policy

Supported Versions

We actively support the following versions of mvn-tree-visualizer:

Version Supported
1.5.x
1.4.x
1.3.x
1.2.x
1.1.x
1.0.x

Reporting a Vulnerability

If you discover a security vulnerability in mvn-tree-visualizer, please report it to us responsibly.

How to Report

  1. Do not create a public GitHub issue for security vulnerabilities
  2. Email us directly at: dyka3773@gmail.com
  3. Include the following information:
    • Description of the vulnerability
    • Steps to reproduce
    • Affected versions
    • Potential impact
    • Suggested fix (if available)

Response Timeline

  • Acknowledgment: We will acknowledge receipt of your report as soon as possible (usually within 48 hours)
  • Assessment: We will assess the vulnerability within 7 days
  • Fix: We will work on a fix and release it as soon as possible
  • Credit: We will credit you in the security advisory (unless you prefer to remain anonymous)

Security Best Practices

When using mvn-tree-visualizer:

  1. Keep updated: Always use the latest version
  2. Validate inputs: Be cautious with dependency files from untrusted sources
  3. File permissions: Ensure proper file permissions on generated outputs
  4. CI/CD: Use in secure CI/CD environments

Scope

This security policy applies to:

  • The mvn-tree-visualizer Python package
  • Official GitHub repository
  • Documentation and examples

Thank you for helping keep mvn-tree-visualizer secure!

There aren’t any published security advisories