Skip to content
This repository has been archived by the owner on Apr 19, 2022. It is now read-only.

Security issue #64

Open
vdeturckheim opened this issue Dec 25, 2017 · 8 comments
Open

Security issue #64

vdeturckheim opened this issue Dec 25, 2017 · 8 comments

Comments

@vdeturckheim
Copy link

Hello,

As a member of the Node.js ecosystem security team I have been reported a security issue regarding this package.

I have contacted the person I identified as maintainer by email but did not get any answer. What is the best way to reach someone with commit rights over this repo do privately explain what is the issue?

Best
Vladimir de Turckheim

@danielpacak
Copy link
Contributor

Hi @vdeturckheim . I'm the only maintainer of this repo / npm module. Feel free to open a PR with the fix for the above mentioned vulnerability.

@vdeturckheim
Copy link
Author

Hey @danielpacak thanks for your response, as a collection and triage team, we only coordinate security issues. Can I invite you on HackerOne with your public email address? You'll be able to review the security report that has been issued to us and to discuss with the person who found it.

@danielpacak
Copy link
Contributor

Sure, please send me the invitation so I can review the report.

@vdeturckheim
Copy link
Author

Awesome, you should have received an email from HackerOne.

@omerlh
Copy link

omerlh commented Nov 29, 2018

Any update on this? @vdeturckheim is has been more than 6 months, maybe it's time for public disclosure?

@vdeturckheim
Copy link
Author

@omerlh I will check ASAP

@linonetwo
Copy link

Are this project and organization still under maintenance? I can confirm that npm package is partially functional, workable but with glitches.

@danielpacak
Copy link
Contributor

Are this project and organization still under maintenance? I can confirm that npm package is partially functional, workable but with glitches.

It's not actively developed although any PR is more than welcomed. I'm okey with disclosing any possible security vulnerabilities that it might cause so the community is aware of that.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants