knockout / knockout

Knockout makes it easier to create rich, responsive UIs with JavaScript
http://knockoutjs.com/
Other
10.43k stars 1.52k forks source link

GHSL-2020-347: seeking security contact for your project #2562

Closed anticomputer closed 3 years ago

anticomputer commented 3 years ago

The GitHub Security Lab reported a potential security vulnerability (GHSL-2020-347) in your project (knockout/knockout). We are approaching 90 days since our initial report and as per our coordinated disclosure policy, we intend to publish a public advisory detailing this issue. If you wish to discuss or further coordinate a response to this issue with the GitHub Security Lab, please contact us at securitylab@github.com within the next 7 days in reference to GHSL-2020-347 and we would love to help you resolve these issues. If not, feel free to close this issue and we will proceed with advisory publication on expiration.

mbest commented 3 years ago

I'm confused. What security vulnerability is this referring to?

anticomputer commented 3 years ago

@mbest Brian Hunt and Steven Anderson reached out and I've resent the original report to them on 02/24/2021, if you would also like to receive a copy please let me know at which email address.