Skip to content

Security: websockets/ws

SECURITY.md

Security Guidelines

Reporting a Vulnerability

Please report security vulnerabilities privately via GitHub Private Vulnerability Reporting. Feedback is generally provided within 72 hours. If no response is received within that time frame, please follow up directly with the maintainers. Email addresses for the lead developers can be found in the git commit history, for example, by running the following command:

git --no-pager show -s --format='%an <%ae>' <gitsha>

where <gitsha> is the SHA of their latest commit in the project.

Once the report is acknowledged and the vulnerability is confirmed, a fix will be developed in collaboration with the reporter and a public security advisory published on GitHub Security Advisories.

History

Learn more about advisories related to websockets/ws in the GitHub Advisory Database