- PatternDef.validate + Luhn-gated credit-card detection; de-overlap the generic phone/date/IP patterns; presets.swiss unchanged (production behavior) - strip g/y flags from nameHint so .test() is stateless (latent footgun) - openAICompatibleProvider: bounded retry on transient failures (network / timeout / 429 / 5xx), configurable via retries + retryDelayMs - eslint + prettier + vitest coverage (97%); CI runs lint/format/coverage - docs: README badges + new-option docs, SECURITY.md, issue/PR templates 26 tests passing; build emits ESM+CJS+types. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
29 lines
1.2 KiB
Markdown
29 lines
1.2 KiB
Markdown
# Security Policy
|
|
|
|
## Reporting a vulnerability
|
|
|
|
This library handles personal data, so we take security and privacy issues seriously — especially any
|
|
path that could cause PII to **leak** (e.g. a placeholder that isn't restored, or sensitive text reaching
|
|
a downstream service un-anonymized).
|
|
|
|
**Please do not open a public issue for security problems.** Instead, email **security@mobiletic.com**
|
|
with:
|
|
|
|
- a description of the issue and its impact,
|
|
- steps to reproduce (a minimal code sample or failing test is ideal),
|
|
- the package version and Node.js version.
|
|
|
|
We aim to acknowledge reports within a few business days and will keep you updated on remediation. Once a
|
|
fix is released, we're happy to credit you (unless you prefer to remain anonymous).
|
|
|
|
## Supported versions
|
|
|
|
This project is pre-1.0; security fixes land on the latest published release. We recommend always running
|
|
the most recent version.
|
|
|
|
## Scope & disclaimer
|
|
|
|
This library is a **best-effort** pseudonymization aid, not a guarantee of regulatory compliance. LLM and
|
|
regex detection can miss or misclassify data. Validate against your own requirements (nLPD, GDPR, HIPAA, …)
|
|
before relying on it for regulated data.
|