ui-ux-pro-max-skill/SECURITY.md
Yassire 1b774be863 chore: repo health files, CI test wiring, and Playwright e2e smoke test
- Add SECURITY.md and CODE_OF_CONDUCT.md (community health was at 50%)
- Add bug/feature issue templates and a PR template
- Wire the existing pytest suite under .claude/skills/*/scripts/tests into
  a new CI workflow; the test docstrings claimed "the existing pytest CI
  runs them" but no workflow actually did
- Add @playwright/test to cli/ with a smoke test that loads the shipped
  preview/xiaomaomi-app.html and asserts no console errors
- Fix a malformed SVG path (invalid `d` attribute) in
  preview/xiaomaomi-app.html found by that new test, replacing it with
  the equivalent valid paw icon path already used elsewhere in the file
2026-07-03 21:25:03 -04:00

36 lines
1.5 KiB
Markdown

# Security Policy
## Supported Versions
Only the latest released version of `ui-ux-pro-max-cli` and the latest `main` branch of this skill receive security fixes.
| Version | Supported |
|---------|-----------|
| Latest release | ✅ |
| Older releases | ❌ |
## Reporting a Vulnerability
Please **do not** open a public GitHub issue for security vulnerabilities.
Instead, report it privately using [GitHub's private vulnerability reporting](https://github.com/nextlevelbuilder/ui-ux-pro-max-skill/security/advisories/new) (Security tab → "Report a vulnerability").
Include as much of the following as possible:
- A description of the vulnerability and its potential impact
- Steps to reproduce (command, prompt, or CLI flags used)
- The version of `ui-ux-pro-max-cli` and the AI assistant/platform involved
- Any relevant logs or output
We aim to acknowledge reports within 5 business days and to provide a fix or mitigation timeline within 14 days for confirmed issues.
## Scope
This project is a design-system generation skill: a Python search/CLI tool and static data (CSV/JSON) consumed by AI coding assistants. In-scope concerns include:
- Arbitrary code execution via the CLI installer or search scripts
- Path traversal or unsafe file writes when running `uipro init` / `uipro uninstall`
- Supply-chain issues in the `ui-ux-pro-max-cli` npm package or its release pipeline
Out of scope: the design output itself (colors, fonts, UI recommendations) is not a security surface.