Skip to content

Security: aimasteracc/tree-sitter-analyzer

Security

.github/SECURITY.md

Security Policy

Supported Versions

Version Supported
0.2.x
0.1.x

Reporting a Vulnerability

We take security seriously. If you discover a security vulnerability in Tree-sitter Analyzer, please report it responsibly.

How to Report

  1. DO NOT create a public GitHub issue for security vulnerabilities
  2. Email the maintainers directly or use GitHub's private vulnerability reporting
  3. Include as much detail as possible:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

What to Expect

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Resolution Timeline: Depends on severity
    • Critical: 24-48 hours
    • High: 7 days
    • Medium: 30 days
    • Low: 90 days

Safe Harbor

We will not pursue legal action against security researchers who:

  • Make a good faith effort to avoid privacy violations, destruction of data, and interruption of services
  • Only interact with accounts you own or with explicit permission
  • Report vulnerabilities through our responsible disclosure process
  • Give us reasonable time to address issues before public disclosure

Security Best Practices

When using Tree-sitter Analyzer:

  • Always use the latest version
  • Review third-party plugins before use
  • Run in isolated environments when analyzing untrusted code

There aren’t any published security advisories