mirror of
https://github.com/nextlevelbuilder/ui-ux-pro-max-skill.git
synced 2026-07-31 18:36:13 +00:00
- Add SECURITY.md and CODE_OF_CONDUCT.md (community health was at 50%) - Add bug/feature issue templates and a PR template - Wire the existing pytest suite under .claude/skills/*/scripts/tests into a new CI workflow; the test docstrings claimed "the existing pytest CI runs them" but no workflow actually did - Add @playwright/test to cli/ with a smoke test that loads the shipped preview/xiaomaomi-app.html and asserts no console errors - Fix a malformed SVG path (invalid `d` attribute) in preview/xiaomaomi-app.html found by that new test, replacing it with the equivalent valid paw icon path already used elsewhere in the file
36 lines
1.5 KiB
Markdown
36 lines
1.5 KiB
Markdown
# Security Policy
|
|
|
|
## Supported Versions
|
|
|
|
Only the latest released version of `ui-ux-pro-max-cli` and the latest `main` branch of this skill receive security fixes.
|
|
|
|
| Version | Supported |
|
|
|---------|-----------|
|
|
| Latest release | ✅ |
|
|
| Older releases | ❌ |
|
|
|
|
## Reporting a Vulnerability
|
|
|
|
Please **do not** open a public GitHub issue for security vulnerabilities.
|
|
|
|
Instead, report it privately using [GitHub's private vulnerability reporting](https://github.com/nextlevelbuilder/ui-ux-pro-max-skill/security/advisories/new) (Security tab → "Report a vulnerability").
|
|
|
|
Include as much of the following as possible:
|
|
|
|
- A description of the vulnerability and its potential impact
|
|
- Steps to reproduce (command, prompt, or CLI flags used)
|
|
- The version of `ui-ux-pro-max-cli` and the AI assistant/platform involved
|
|
- Any relevant logs or output
|
|
|
|
We aim to acknowledge reports within 5 business days and to provide a fix or mitigation timeline within 14 days for confirmed issues.
|
|
|
|
## Scope
|
|
|
|
This project is a design-system generation skill: a Python search/CLI tool and static data (CSV/JSON) consumed by AI coding assistants. In-scope concerns include:
|
|
|
|
- Arbitrary code execution via the CLI installer or search scripts
|
|
- Path traversal or unsafe file writes when running `uipro init` / `uipro uninstall`
|
|
- Supply-chain issues in the `ui-ux-pro-max-cli` npm package or its release pipeline
|
|
|
|
Out of scope: the design output itself (colors, fonts, UI recommendations) is not a security surface.
|