Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Trying to get in touch regarding a security issue #146

Closed
JamieSlome opened this issue Sep 17, 2021 · 6 comments
Closed

Trying to get in touch regarding a security issue #146

JamieSlome opened this issue Sep 17, 2021 · 6 comments

Comments

@JamieSlome
Copy link

Hey there!

I'd like to report a security issue but cannot find contact instructions on your repository.

If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.

Thank you for your consideration, and I look forward to hearing from you!

(cc @huntr-helper)

@isaacs
Copy link
Owner

isaacs commented Feb 5, 2022

Hi. You can email me at i@izs.me and I'll be happy to take a look.

@JamieSlome
Copy link
Author

@isaacs - thanks for your response! 👍

Looks like we sent you a couple of e-mails a few months back - if it is easier for you, you can view the report directly here:

https://huntr.dev/bounties/e4e1393c-d590-4492-9f43-8be3f3321629/

@stevepae
Copy link

stevepae commented Feb 9, 2022

@JamieSlome I'm having the same issue with a security scan. I see that the issue may have been resolved. Are your security scans still sending you this issue? If not, could you tell me how you were able to resolve it on your end?

@isaacs
Copy link
Owner

isaacs commented Feb 9, 2022

This was corrected and the bounty awarded. Upgrade to the latest version, the redos was corrected.

@isaacs isaacs closed this as completed Feb 9, 2022
@stevepae
Copy link

@isaacs how do i upgrade to the latest version?

@isaacs
Copy link
Owner

isaacs commented Feb 21, 2022

npm update minimatch

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants