mysqljs / mysql

A pure node.js JavaScript Client implementing the MySQL protocol.
MIT License
18.31k stars 2.53k forks source link

Trying to get in touch regarding a security issue #2521

Closed JamieSlome closed 3 years ago

JamieSlome commented 3 years ago

Hey there!

I'd like to report a security issue but cannot find contact instructions on your repository.

If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.

Thank you for your consideration, and I look forward to hearing from you!

(cc @huntr-helper)

dougwilson commented 3 years ago

https://github.com/mysqljs/mysql#security-issues

dougwilson commented 3 years ago

Baesd on your issue history this looks like a boilerplate issue, and probably never even looked a the readme. You can email me at the following. Please include the information requested in the report instructions, mainly include PoC. https://github.com/mysqljs/mysql/blob/3430c513d6b0ca279fb7c79b210c9301e9315658/package.json#L10