ericf / express-handlebars

A Handlebars view engine for Express which doesn't suck.
BSD 3-Clause "New" or "Revised" License
2.31k stars 384 forks source link

Security Contact Needed #290

Closed agustingianni closed 3 years ago

agustingianni commented 3 years ago

Hello,

I am a member of the GitHub Security Lab (https://securitylab.github.com).

I've attempted to reach a maintainer for this project to report a potential security issue but have been unable to verify the report was received. Please could a project maintainer contact us at securitylab@github.com, or provide an email address so we can contact you.

Thank you, Agustin Gianni (@agustingianni) GitHub Security Lab

UziTech commented 3 years ago

All new development of express-handlebars is done on a new repo express-handlebars/express-handlebars.

You can email me at tony@brix.ninja if you have security concerns.

UziTech commented 3 years ago

If the concern is with this repo and not the npm package express-handlebars then good luck reaching @ericf I tried for a while and eventually had to fork it.

agustingianni commented 3 years ago

Hello @UziTech thank you for the answer! I will contact you if there is any concerns about your fork. Thanks again.