Security reports should target the latest released version. UIAtlas follows
semantic versioning from 1.0.0; security fixes are released as patch versions
when they do not require a breaking change.
Please do not open a public issue for a security vulnerability.
Use GitHub's private vulnerability reporting for this repository:
- Open the repository on GitHub.
- Go to Security.
- Choose Report a vulnerability.
- Submit the details privately.
Include:
- A description of the issue
- Steps to reproduce
- Impact and affected versions, if known
- Any suggested mitigation
If private vulnerability reporting is unavailable, open a public issue asking for a private contact channel, but do not include vulnerability details.
UIAtlas generates static reports from local manifests and image files. Security-sensitive areas include:
- Path traversal or unsafe file copying
- Malicious manifest content rendered into HTML
- Unsafe handling of generated report assets
- CI workflows that publish unintended local files
Generated reports should be treated as artifacts from trusted project inputs.