Security Policy
March 29, 2026 ยท View on GitHub
Supported Versions
| Version | Supported |
|---|---|
| 0.2.x | :white_check_mark: |
| < 0.2 | :x: |
Reporting a Vulnerability
If you discover a security vulnerability in mex, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
Instead, please email thedakshjaitly@gmail.com with:
- A description of the vulnerability
- Steps to reproduce the issue
- The potential impact
- Any suggested fixes (optional)
What to Expect
- Acknowledgment within 48 hours of your report
- Status update within 7 days with an assessment and next steps
- Fix timeline depends on severity โ critical issues will be prioritized
Scope
This policy applies to the mex CLI tool and its published npm package. Third-party dependencies are outside the scope of this policy, but we appreciate being notified if you find issues in our dependency chain.
Thank you for helping keep mex secure.