jfsiii / chromath

JavaScript color conversion and manipulation functions
https://jfsiii.github.io/chromath/
190 stars 13 forks source link

Trying to get in touch regarding a security issue #12

Open JamieSlome opened 3 years ago

JamieSlome commented 3 years ago

Hey there!

I'd like to report a security issue but cannot find contact instructions on your repository.

If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.

Thank you for your consideration, and I look forward to hearing from you!

(cc @huntr-helper)

yetingli commented 2 years ago

Hi John @jfsiii , recently I found a potential ReDoS vulnerability inside chromath and made a patch for it. I hope these can help you. You can access the vulnerability details at huntr. Please feel free to get in touch if there are any more issues.