ossf / package-analysis

Open Source Package Analysis
Apache License 2.0
714 stars 51 forks source link

Report a critical issue #1041

Closed ya3raj closed 2 months ago

ya3raj commented 3 months ago

Hi there, How do i report a vulnerability to ossf, which i discovered in npm package. Could you please guide me if there is any Bug bounty program or so?

maxfisher-g commented 3 months ago

Hi @ya3raj, please report this vulnerability to NPM, and contact the package author. If you believe the package is doing something malicious, you can use the "Report malware" button on the NPM page.

I'm not aware of any bug bounties for third party packages (i.e packages not published by OpenSSF or any of its constituents).