thinwrap/location follows semantic versioning. Security fixes land on the
latest 1.x release line. Pin to ^1.0 to receive them.
Please report security issues privately — do not open a public GitHub issue for anything security-sensitive.
- Preferred: open a private security advisory on the repository (GitHub → Security → Report a vulnerability).
- Alternatively, email security@thinwrap.dev with the details.
Please include a description, affected versions, and a minimal reproduction if you have one.
- Acknowledgement of your report: within 3 business days.
- Initial assessment and severity triage: within 7 business days.
- We will keep you updated on remediation progress and coordinate a disclosure timeline with you before any public advisory.
Releases are cosign-signed via GitHub Actions OIDC (no static signing keys); maintainer accounts require two-factor authentication (TOTP via an authenticator app). Packagist consumes the package via webhook auto-sync — no long-lived Packagist API token is stored.