braintree / sanitize-url

MIT License
307 stars 35 forks source link

Enable private vulnerability reporting #48

Closed Panya closed 1 year ago

Panya commented 1 year ago

Hi there.

I've found a security issue in your library. Can you enable the newly deployed feature of GitHub (https://docs.github.com/en/code-security/security-advisories/repository-security-advisories/configuring-private-vulnerability-reporting-for-a-repository), so I can share the details?

I also reported it to https://huntr.dev. The issue should be accessible to you by this URL: https://huntr.dev/bounties/8879054f-80a7-457c-bf17-a4ecd4b73a28/

hollabaq86 commented 1 year ago

👋 We take security vulnerabilities very seriously and appreciate your help notifying us of vulnerabilities in a responsible manner. If you encounter any security vulnerabilities, please submit them to PayPal’s Bug Bounty Program. If you have any questions, please reach out to ppbugbounty@paypal.com.