tj / ejs

Embedded JavaScript templates for node
4.47k stars 512 forks source link

Security Contact Needed #256

Closed agustingianni closed 3 years ago

agustingianni commented 3 years ago

Hello,

I am a member of the GitHub Security Lab (https://securitylab.github.com).

I've attempted to reach a maintainer for this project to report a potential security issue but have been unable to verify the report was received. Please could a project maintainer contact us at securitylab@github.com, or provide an email address so we can contact you.

Thank you, Agustin Gianni (@agustingianni) GitHub Security Lab

mde commented 3 years ago

This project is deprecated, and only online for historical interest.

I was a contributor, not the owner — I am however the owner and maintainer of the current version on NPM (https://github.com/mde/ejs).

On Thu, Jan 28, 2021 at 1:14 AM Agustin Gianni notifications@github.com wrote:

Hello,

I am a member of the GitHub Security Lab (https://securitylab.github.com).

I've attempted to reach a maintainer for this project to report a potential security issue but have been unable to verify the report was received. Please could a project maintainer contact us at securitylab@github.com, or provide an email address so we can contact you.

Thank you, Agustin Gianni (@agustingianni https://github.com/agustingianni) GitHub Security Lab

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/tj/ejs/issues/256, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAAAF5MIA6SRTK73NME32O3S4ETH7ANCNFSM4WWV2OJQ .

agustingianni commented 3 years ago

Hello @mde thanks for the answer, I will contact you then.

aparameswaran commented 3 years ago

Hi @agustingianni and @mde, quick question to both of you. Since this thread is closed, I am not sure if the security vulnerability reported has been addressed or not. Can you please confirm?

mde commented 3 years ago

This project is deprecated, and no longer supported. Please direct questions to current version on NPM (https://github.com/mde/ejs).