Security fixes go into the latest release of each package. Before reporting, check that the problem still happens on the current version of qsu for JavaScript, Dart or Python.
To report a security vulnerability, open a draft security advisory on GitHub: https://github.com/jooy2/qsu/security/advisories/new
Do not report a vulnerability as a general issue, and do not describe it in a pull request before it is fixed. If you cannot use the advisory page, write to the maintainers at https://cdget.com/contact and wait for a reply before disclosing anything.
A report is easier to act on when it includes:
- The package and version it affects, and the runtime you ran it on.
- The steps to reproduce it, with the smallest example that shows the problem.
- What an attacker gains from it.
- A patch or a workaround, if you already have one.
Project maintainers are quickly addressing reported security vulnerabilities in the project and providing relevant patches.
We report these to the relevant users and handle the correspondence to prevent the issue from recurring.
We recommend that users of project sources use the latest version, which addresses possible security vulnerabilities.
- Contact page: https://cdget.com/contact