Skip to content

Security: storagesdk/.github

Security

SECURITY.md

Security policy

Reporting a vulnerability

Open a private security advisory — do not file a public issue:

Useful to include:

  • What the issue is and what an attacker could do with it.
  • Steps to reproduce, or a minimal proof-of-concept.
  • Versions you tested (package, Node, adapter, backend).
  • A suggested fix, if you have one.

Once a fix lands, we publish a GitHub Security Advisory and a patched release. Reporters are credited unless they prefer to stay anonymous.

Scope

All repositories in the storagesdk GitHub organization, including @storagesdk/core and @storagesdk/adapters.

Vulnerabilities in upstream dependencies should be reported to those projects directly.

There aren't any published security advisories