storybookjs / telejson

🛰 JSON parse & stringify with support for cyclic objects, functions, dates, regex, infinity, undefined, null, NaN, Classes, Instances
MIT License
169 stars 28 forks source link

Security concern #91

Open benharvie opened 1 year ago

benharvie commented 1 year ago

Hello 👋

I run a security community that finds and fixes vulnerabilities in OSS. A researcher (@pperk) has found a potential issue, which I would be eager to share with you.

Could you add a SECURITY.md file with an e-mail address for me to send further details to? GitHub recommends a security policy to ensure issues are responsibly disclosed, and it would help direct researchers in the future.

Looking forward to hearing from you 👍

(cc @huntr-helper)

BossElijah commented 2 months ago

I don't know, but I assume the policy is the same here as in the main storybook repo: https://github.com/storybookjs/storybook/security/policy

Originally posted by @SimenB in https://github.com/storybookjs/telejson/issues/76#issuecomment-937832145

https://github.com/storybookjs/telejson/issues/76#issuecomment-937832145