Open a private security advisory — do not file a public issue:
storagesdk/storagesdk→ https://github.com/storagesdk/storagesdk/security/advisories/new
Useful to include:
- What the issue is and what an attacker could do with it.
- Steps to reproduce, or a minimal proof-of-concept.
- Versions you tested (package, Node, adapter, backend).
- A suggested fix, if you have one.
Once a fix lands, we publish a GitHub Security Advisory and a patched release. Reporters are credited unless they prefer to stay anonymous.
All repositories in the storagesdk GitHub organization, including @storagesdk/core and @storagesdk/adapters.
Vulnerabilities in upstream dependencies should be reported to those projects directly.