ianstormtaylor / superstruct

A simple and composable way to validate data in JavaScript (and TypeScript).
https://docs.superstructjs.org
MIT License
6.96k stars 223 forks source link

Please provide security reporting information or enable advisories #1179

Open ritave opened 1 year ago

ritave commented 1 year ago

I use Superstruct in an extremely hostile and adversarial environment and have identified few security issues which allows a malicious actor to bypass validation.

Please provide a SECURITY.md file with information on how to report such issues, or enable GitHub's Security Advisories so that I can report, and hopefully create a Pull Request against