mirror of
https://github.com/nextlevelbuilder/ui-ux-pro-max-skill.git
synced 2026-07-31 18:36:13 +00:00
- Add SECURITY.md and CODE_OF_CONDUCT.md (community health was at 50%) - Add bug/feature issue templates and a PR template - Wire the existing pytest suite under .claude/skills/*/scripts/tests into a new CI workflow; the test docstrings claimed "the existing pytest CI runs them" but no workflow actually did - Add @playwright/test to cli/ with a smoke test that loads the shipped preview/xiaomaomi-app.html and asserts no console errors - Fix a malformed SVG path (invalid `d` attribute) in preview/xiaomaomi-app.html found by that new test, replacing it with the equivalent valid paw icon path already used elsewhere in the file
1.5 KiB
1.5 KiB
Security Policy
Supported Versions
Only the latest released version of ui-ux-pro-max-cli and the latest main branch of this skill receive security fixes.
| Version | Supported |
|---|---|
| Latest release | ✅ |
| Older releases | ❌ |
Reporting a Vulnerability
Please do not open a public GitHub issue for security vulnerabilities.
Instead, report it privately using GitHub's private vulnerability reporting (Security tab → "Report a vulnerability").
Include as much of the following as possible:
- A description of the vulnerability and its potential impact
- Steps to reproduce (command, prompt, or CLI flags used)
- The version of
ui-ux-pro-max-cliand the AI assistant/platform involved - Any relevant logs or output
We aim to acknowledge reports within 5 business days and to provide a fix or mitigation timeline within 14 days for confirmed issues.
Scope
This project is a design-system generation skill: a Python search/CLI tool and static data (CSV/JSON) consumed by AI coding assistants. In-scope concerns include:
- Arbitrary code execution via the CLI installer or search scripts
- Path traversal or unsafe file writes when running
uipro init/uipro uninstall - Supply-chain issues in the
ui-ux-pro-max-clinpm package or its release pipeline
Out of scope: the design output itself (colors, fonts, UI recommendations) is not a security surface.