Security
Supported versions
Both packages are pre-1.0. tbtop/admin and its @tbtop/inertia-admin client ship in lockstep, and only the latest release is supported. Upgrade before reporting against an older one. For tbtop/cms, only the latest 0.x minor receives security fixes; older minors are not patched. Once a package reaches 1.0, this policy moves to standard semver support — fixes on the latest major, with backports considered case by case.
Reporting a vulnerability
Report vulnerabilities privately — through a GitHub security advisory or by email — never in a public issue. A public issue gives an attacker a head start before a fix ships.
tbtop/admin— the PHP DSL and the@tbtop/inertia-adminclient: open a private advisory, or email support@divotek.com.tbtop/cms— the page/block CMS, its admin pages and the frontend rendering it ships. The repository is a closed beta for now; report a vulnerability the same way astbtop/adminabove and it will be triaged against the CMS source directly.
Include the affected package and version, steps to reproduce and the potential impact. Reports are handled privately by the maintainers; expect an acknowledgment within a few business days.
The policy covers the packages themselves. Issues in a host application's own code, or in third-party dependencies this project does not maintain, are outside its scope.
security.txt
The same contacts are published in machine-readable form at /.well-known/security.txt.