jerryscript-project / jerryscript

Ultra-lightweight JavaScript engine for the Internet of Things.
https://jerryscript.net
Apache License 2.0
6.93k stars 671 forks source link

Who to contact for security issues #5103

Open psmoros opened 11 months ago

psmoros commented 11 months ago

Hello 👋

I run a security community that finds and fixes vulnerabilities in OSS. A researcher (@gandalf4a) has found a potential issue, which I would be eager to share with you.

Could you add a SECURITY.md file with an e-mail address for me to send further details to? GitHub recommends a security policy to ensure issues are responsibly disclosed, and it would help direct researchers in the future.

Looking forward to hearing from you 👍

(cc @huntr-helper)