Skip to content

Security: bpmn-io/bpmn-js

SECURITY.md

Security

Camunda takes security bugs in the our software products seriously. This covers source code repositories managed through our GitHub organizations, including Camunda and bpmn.io.

If you believe you have found a security vulnerability in the Camunda Modeler or a bpmn.io library, please report it to us as described below. Head over to the Camunda security page to report vulnerabilities in other Camunda products.

Please do not report security vulnerabilities through public GitHub issues.

Reporting Security Issues

We appreciate your efforts to responsibly disclose your findings, and will make every effort to acknowledge your contributions.

To report a security issue, email modeling@camunda.com and include the word "SECURITY" in the subject line.

The development team will send a response indicating the next steps in handling your report. After the initial reply to your report, we will keep you informed of the progress towards a fix and full announcement, and may ask for additional information or guidance.

Please report security bugs in third-party modules to the person or team maintaining the module. You can also report a vulnerability through the npm contact form by selecting "I'm reporting a security vulnerability".

There aren’t any published security advisories