denali-js / core

An opinionated, ORM agnostic framework for building robust JSON APIs in Node
http://denalijs.org
Apache License 2.0
73 stars 14 forks source link

Security reporting procedure #403

Open davewasmer opened 6 years ago

seawatts commented 6 years ago

Can you provide more detail here?

davewasmer commented 6 years ago

We should have a written, publicly available process for responsibly reporting security flaws in the framework. Something that documents how to privately report such issues, timeliness for communication, etc. This is standard procedure for mature frameworks, and beyond the intrinsic value of the procedure, is a signal of the seriousness of the project.

For example: https://emberjs.com/security/