intridea / multi_json

A generic swappable back-end for JSON handling.
http://rdoc.info/projects/intridea/multi_json
MIT License
757 stars 129 forks source link

Where do security issues belong? #200

Closed xxx closed 4 years ago

xxx commented 4 years ago

Hi,

Who do I contact regarding potential vulnerabilities? I'd rather not just post it publicly, but will do so in a week if I don't hear anything. I have a failing spec that I believe should pass, which quickly shows what we're seeing.

This is on version 1.15.0

rwz commented 4 years ago

Hi,

MultiJSON is not being actively maintained, but if the issue is something that can be addressed relatively easily, I'll be happy to take a look.

Feel free to send the details to pavel@pravosud.com

xxx commented 4 years ago

closing this since contact has been made privately.

yangqinglin commented 3 years ago

same issue.