Security Policy

Supported Versions

Security fixes are applied to the latest code on the default branch. Older commits, tags, and forks are not maintained; please reproduce findings against the most recent code before reporting.

Reporting a Vulnerability

If you believe you have found a security vulnerability, please report it to us as soon as possible. We take all reports seriously and will do our best to address the issue promptly.

Do not create a public GitHub issue for the security vulnerability.

Instead, please follow these steps:

  1. Email us at blocks@selisegroup.com with details of the vulnerability.
  2. Include a thorough description of the issue, including any relevant information on the environment in which the vulnerability was discovered.
  3. Allow some time for us to review and respond to your report.

What to Expect

Responsible Disclosure

We appreciate the efforts of security researchers and the community in helping to keep our project and users safe. If you responsibly disclose a security issue, we commit to:

Scope

This security policy applies to the MailCraft email editor (the <mailcraft-editor> web component and this repository). Please note that this policy does not give you permission to hack, harm, or exploit our services. Any such attempts will be considered malicious and may be reported to the appropriate authorities.

Security-relevant surfaces particular to this package

When reviewing, pay special attention to the paths this package deliberately hardens:

Updates

We may update this security policy from time to time. Check the file’s Git history for the most recent changes.

Thank you for helping to keep MailCraft secure!