Hi there,
I couldn't find a SECURITY.md
in your repository and am not sure how to best contact you privately to disclose a security issue.
Can you add a SECURITY.md
file with an e-mail to your repository, so that our system can send you the vulnerability details? GitHub suggests that a security policy is the best way to make sure security issues are responsibly disclosed.
Once you've done that, you should receive an e-mail within the next hour with more info.
Thanks! (cc @huntr-helper)
1条答案
按热度按时间brccelvz1#
@mengshukeji - just a heads up that we have received the following vulnerability reports:
https://www.huntr.dev/bounties/1-npm-luckysheet/
https://huntr.dev/bounties/4dbf5fde-dedd-462e-9567-d0d9fe903a69/
They are both private and only accessible to maintainers with repository write permissions.