docs/INCIDENT_RESPONSE.md
We monitor security reports sent via security outreach, GitHub advisories, issues, and npm notifications.
Check the severity:
We will publish update in our Twitter @postcss and PostCSS’s wiki.
We will release CVE for Critical/High issues. We prefer to not release CVE for Low issues since we have small number of such users (but could change our minds depends on the issue).