Skip to content

Trying to get in touch regarding a security issue #4

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
zidingz opened this issue Sep 4, 2021 · 2 comments
Open

Trying to get in touch regarding a security issue #4

zidingz opened this issue Sep 4, 2021 · 2 comments

Comments

@zidingz
Copy link

zidingz commented Sep 4, 2021

Hey there!

I'd like to report a security issue but cannot find contact instructions on your repository.

If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.

Thank you for your consideration, and I look forward to hearing from you!

(cc @huntr-helper)

@yetingli
Copy link

Hey Steve, recently I found a potential ReDoS vulnerability inside html-comment-regex, I made a patch for it and hope you are happy to receive this fix. You can access the vulnerability details at huntr. Please feel free to get in touch if there are any more issues.

@stevemao
Copy link
Owner

stevemao commented Oct 1, 2024

Please either send me an email, or send a PR to fix it directly.

@zidingz @huntr-helper @yetingli

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants