deoxxa / dotty

Access properties of nested objects using dot-path notation
BSD 3-Clause "New" or "Revised" License
128 stars 20 forks source link

Trying to get in touch regarding a security issue #31

Closed zidingz closed 2 years ago

zidingz commented 3 years ago

Hey there!

I'd like to report a security issue but cannot find contact instructions on your repository.

If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.

Thank you for your consideration, and I look forward to hearing from you!

(cc @huntr-helper)

stramel commented 3 years ago

Hello! Unfortunately, i don't have access to the main settings of this repository and can't issue security disclosures through GitHub or npm. I will try to add a security.md file as you suggested in the meantime. You can email me directly and I can add it a fix for the vulnerability.