Security fixes are only applied to the latest major release line.
| Version | Supported |
|---|---|
| 3.x | ✅ |
| 2.x | ❌ |
| < 2.0 | ❌ |
Please do not open a public GitHub issue for security reports.
Use GitHub's private vulnerability reporting instead:
We'll acknowledge your report within 7 days and keep you updated on the fix. Once a patch is released, you'll be credited in the advisory (unless you prefer to stay anonymous).
In scope:
- The
ProfanityEngineruntime code inindex.jsandsrc/. - The published data files in
data/. - The GitHub Actions workflows in
.github/workflows/.
Out of scope:
- Issues in
devDependenciesonly (Jest, Prettier) that don't affect the shipped package. - The words themselves being offensive — that is, by design, the point of the library.