Skip to content

Security: winkjs/wink-nlp

Security

SECURITY.md

Security

Security of all WinkJS packages, including winkNLP is important to us.

Supported Versions

Only the latest version of winkNLP is supported. This version can be installed and/or downloaded from NPM or from the latest GitHub release.

Reporting a Vulnerability

We would appreciate responsible disclosure. If you would like to report a vulnerability, the preferred way to do so is contacting us directly. Please do not report security vulnerabilities through public GitHub issues.

Please include the following minimum information to help us understand and analyze the potential issue:

  1. Type of issue for example buffer overflow or privilege escalation.
  2. Full path(s) of source file(s) related to the issue including the affected source code’s tag or commit SHA.
  3. Step-by-step instructions on how to reproduce the issue, including the sample exploit code
  4. Impact of the issue.

When you are investigating and reporting the vulnerability you must never:

  1. break any law,
  2. tell others about the vulnerability you have found until we have disclosed it, and/or
  3. demand money to disclose a vulnerability.

There aren’t any published security advisories