We give security updates to these versions:
| Version | Supported |
|---|---|
| >= 3.0.0 | ✅ |
The cnpmcore team and the community give full attention to all security vulnerabilities. Thank you for your work to make our open source software more secure. We value your effort and your responsible disclosure. We will give you credit for your contribution.
Do not report security vulnerabilities in public GitHub issues, discussions, or pull requests.
Send your report with GitHub private vulnerability reporting:
https://github.com/cnpm/cnpmcore/security/advisories/new
A private report has these advantages:
- Only you and the maintainers can read the report.
- All of the discussion stays in one place.
- We can give you credit in the advisory when we publish it.
- We can request a CVE when we release the fix.
Give as much of this information as you can:
- The type of the issue.
- The version or the commit that has the issue.
- The full path of each source file that relates to the issue.
- The steps to reproduce the issue.
- The proof-of-concept code or the exploit code, if you have it.
- The impact of the issue.
- The method that an attacker can use to exploit the issue.
If you cannot use GitHub Security Advisories, send an email to the cnpmcore security team:
fengmk2+cnpmcoresecurity@gmail.com
killa07071201@gmail.com
smith3816@gmail.com
elrrrrrrr@gmail.com
We will confirm that we received your report. We will process the report as soon as possible. We will then tell you the next steps. The security team will tell you about the progress of the fix and the announcement. The team can also ask you for more information.
Report a vulnerability in a third-party module to the person or the team that maintains the module.
The security team assigns each report to a primary handler. The primary handler controls the fix and the release. The handler does these steps:
- Confirm the problem.
- Find the versions that have the problem.
- Examine the code to find related problems.
- Prepare a fix for each release that we maintain.
- Release the fixes to NPM as soon as possible.
- Publish a GitHub Security Advisory after we release the fix. Give credit to the reporter, unless the reporter asks to stay anonymous.