ljharb / js-traverse

MIT License
45 stars 8 forks source link

Potential Security Issue #1

Closed supriza closed 1 year ago

supriza commented 1 year ago

Hi @benatkin @ljharb @karlbohlmark @grncdr @harthur , My name is Raul and I'm a security researcher at Snyk. There might be a security issue in your package. Where can I contact you in private to discuss things? Thanks!

ljharb commented 1 year ago

Hi @supriza; the security policy at https://github.com/ljharb/js-traverse/security/policy should cover this :-)

supriza commented 1 year ago

Thanks @ljharb, I missed that!

benatkin commented 1 year ago

such willingness to waste my time _._

more inclined to go w/ socket.dev now =)

ljharb commented 1 year ago

@benatkin i'm not sure what you mean?

benatkin commented 1 year ago

@ljharb I mean a security researcher from Snyk mentioned my name in a list and didn't check for a security policy

not a big deal I guess :)

ljharb commented 1 year ago

Going to close this for now.