mmckegg / notevil

Evalulate javascript like the built-in javascript eval() method but safely.
195 stars 24 forks source link

Trying to get in touch regarding a security issue #42

Open JamieSlome opened 3 years ago

JamieSlome commented 3 years ago

Hi there,

I couldn't find a SECURITY.md in your repository and am not sure how to best contact you privately to disclose a security issue.

Can you add a SECURITY.md file with an e-mail to your repository, so that our system can send you the vulnerability details? GitHub suggests that a security policy is the best way to make sure security issues are responsibly disclosed.

Once you've done that, you should receive an e-mail within the next hour with more info.

Thanks! (cc @huntr-helper)

drj-io commented 2 years ago

Big red flag here. Thanks for posting, using something else.

mmckegg commented 2 years ago

Yeah this is unmaintained at this point. I should mark this as archived and deprecated on npm. Thanks for the reminder.