Skip to content

Security: jooy2/qsu

Security

SECURITY.md

Security Policy

Supported Versions

Security fixes go into the latest release of each package. Before reporting, check that the problem still happens on the current version of qsu for JavaScript, Dart or Python.

Reporting Security Issues

To report a security vulnerability, open a draft security advisory on GitHub: https://github.com/jooy2/qsu/security/advisories/new

Do not report a vulnerability as a general issue, and do not describe it in a pull request before it is fixed. If you cannot use the advisory page, write to the maintainers at https://cdget.com/contact and wait for a reply before disclosing anything.

A report is easier to act on when it includes:

  • The package and version it affects, and the runtime you ran it on.
  • The steps to reproduce it, with the smallest example that shows the problem.
  • What an attacker gains from it.
  • A patch or a workaround, if you already have one.

Security compliance

Project maintainers are quickly addressing reported security vulnerabilities in the project and providing relevant patches.

We report these to the relevant users and handle the correspondence to prevent the issue from recurring.

Security recommendations

We recommend that users of project sources use the latest version, which addresses possible security vulnerabilities.

Contact

There aren't any published security advisories