The full security policy lives in SECURITY.md at the repository root: supported versions, how to report a vulnerability, scope, the enforced security architecture, the update mechanism's threat model, and known limitations. Read that document.
In short:
- Report suspected vulnerabilities privately: Security tab → "Report a vulnerability" (https://github.com/JS-PACKAGE/LINE.js/security/advisories/new). Do not open a public issue.
- Never attach credentials: no
session.json,config.yaml, tokens, QR URLs, PINs, E2EE keys or real message contents. - Test only with your own LINE secondary account and your own machine.
- Supported versions: the latest published release only.
This file exists so GitHub can detect the policy; it is a pointer and MUST NOT duplicate the policy text, so the two can never drift apart.