Skip to content

Security Policy

Syncraft Labs takes the security of our libraries, developer tooling, and downstream users seriously. This document details our version support lifecycle, responsible vulnerability disclosure process, and response service-level agreements (SLAs).


Supported Versions

We actively maintain and provide security patches for the following versions:

PackageVersion RangeSecurity Support Status
@syncraft-labs/core>= 0.4.2Supported (Active)
@syncraft-labs/react>= 0.4.2Supported (Active)
@syncraft-labs/vue>= 0.4.2Supported (Active)
All packages0.4.1Revoked & Deprecated (See Advisory SYNCRAFT-SEC-2026-001)
All packages<= 0.4.0End of Life (EOL) — Please upgrade to latest

Reporting a Vulnerability

If you discover a potential vulnerability, please report it privately rather than creating a public GitHub issue.

Preferred Reporting Method

Submit a private advisory through GitHub Security Advisories. This provides a secure, encrypted workspace where we can collaborate on a fix and coordinate a synchronized release.

Direct Email Contact

If you cannot access GitHub Security Advisories, send an email directly to:

  • Primary Maintainer: denislistiadi24@gmail.com
  • Subject: [SECURITY] Syncraft Labs Vulnerability Report

What to Include in Your Report

  1. Description of the vulnerability and its potential impact.
  2. Affected package(s) and version(s).
  3. Detailed reproduction steps or a minimal Proof of Concept (PoC).
  4. Any potential mitigations or suggested patches.

Response Timeline & SLAs

PhaseTarget SLADescription
Initial Acknowledgment24–48 hoursConfirm receipt of report and open internal tracking
Triage & Validation3–5 business daysReproduce and assess severity/scope
Remediation & PatchBased on severityDevelop fix, run full test suites, and coordinate release
Public AdvisoryUpon releasePublish CVE / GitHub Advisory with credits to reporter

Safe Harbor Policy

We strongly support ethical security research. We will not pursue legal action against researchers who report vulnerabilities in good faith, provided that:

  • You give us reasonable time to investigate and resolve the issue before disclosing it publicly.
  • You do not compromise user data, disrupt system availability, or cause data destruction.
  • You operate within the scope of responsible disclosure.

Historical Advisories