Security reports are considered for the current default branch and the latest
published eslint-plugin-suitescript-compat package version.
Use GitHub private vulnerability reporting for sensitive security reports:
https://github.com/hannasdev/eslint-plugin-suitescript-compat/security/advisories/new
Please do not post sensitive reports in public issues. Avoid including NetSuite account IDs, internal URLs, customer screenshots, credentials, tokens, private keys, proprietary SuiteScript, or other customer-specific material.
Good reports include:
- affected package version or commit
- a short description of the impact
- sanitized reproduction steps or a minimal synthetic example
- whether the concern affects rule behavior, package publication, repository automation, or documentation
Public issues are appropriate for non-sensitive bugs, rule requests, documentation corrections, and hardening suggestions that do not expose private details.
This is a small maintainer-owned project, so response times may vary. Reports will be reviewed with care, but this policy does not promise a fixed response or disclosure timeline.