- PatternDef.validate + Luhn-gated credit-card detection; de-overlap the generic phone/date/IP patterns; presets.swiss unchanged (production behavior) - strip g/y flags from nameHint so .test() is stateless (latent footgun) - openAICompatibleProvider: bounded retry on transient failures (network / timeout / 429 / 5xx), configurable via retries + retryDelayMs - eslint + prettier + vitest coverage (97%); CI runs lint/format/coverage - docs: README badges + new-option docs, SECURITY.md, issue/PR templates 26 tests passing; build emits ESM+CJS+types. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
1.2 KiB
Security Policy
Reporting a vulnerability
This library handles personal data, so we take security and privacy issues seriously — especially any path that could cause PII to leak (e.g. a placeholder that isn't restored, or sensitive text reaching a downstream service un-anonymized).
Please do not open a public issue for security problems. Instead, email security@mobiletic.com with:
- a description of the issue and its impact,
- steps to reproduce (a minimal code sample or failing test is ideal),
- the package version and Node.js version.
We aim to acknowledge reports within a few business days and will keep you updated on remediation. Once a fix is released, we're happy to credit you (unless you prefer to remain anonymous).
Supported versions
This project is pre-1.0; security fixes land on the latest published release. We recommend always running the most recent version.
Scope & disclaimer
This library is a best-effort pseudonymization aid, not a guarantee of regulatory compliance. LLM and regex detection can miss or misclassify data. Validate against your own requirements (nLPD, GDPR, HIPAA, …) before relying on it for regulated data.