lquixada / cross-fetch

Universal WHATWG Fetch API for Node, Browsers and React Native.
MIT License
1.67k stars 104 forks source link

Who to contact for security issues #122

Closed JamieSlome closed 2 years ago

JamieSlome commented 2 years ago

Hey there!

I belong to an open source security research community, and a member (@ranjit-git) has found an issue, but doesn’t know the best way to disclose it.

If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.

Thank you for your consideration, and I look forward to hearing from you!

(cc @huntr-helper)

lquixada commented 2 years ago

@JamieSlome thanks for taking the time to open this issue! A SECURITY.md file has been created.

JamieSlome commented 2 years ago

@lquixada - thanks for creating the SECURITY.md 👍

We will get further details sent over to the elected e-mail address shortly. In the meantime, the report can be accessed directly here: https://huntr.dev/bounties/ab55dfdd-2a60-437a-a832-e3efe3d264ac

It is private and only accessible to you @lquixada 👍

lquixada commented 2 years ago

thanks @JamieSlome ! will take a look!

JamieSlome commented 2 years ago

@lquixada - great, on call if you need me for any support, plus @ranjit-git for any questions regarding the report 😃