To report a security vulnerability, please use the Tidelift security contact. Tidelift will coordinate the fix and disclosure.
If you do not receive an acknowledgement of your report
within 6 business days, or if you cannot find a private
security contact for the project, you may escalate to the
OpenJS Foundation CNA at [email protected].
If the project acknowledges your report but does not provide any further response or engagement within 14 days, escalation is also appropriate.