Skip to content

Security: nodejs/nodejs.org

SECURITY.md

Security

Reporting a vulnerability to Node.js Website

Please report security issues privately using the GitHub Security Advisory workflow (Security → “Report a vulnerability”).

Do not open a public GitHub issue for security problems.

We aim to acknowledge reports within 7 business days. If you do not receive an acknowledgement within 7 business days, forward your report to [email protected].

Disclosure & advisories

Confirmed vulnerabilities will be published as a GitHub Security Advisory (and assigned a CVE when applicable). Notices are also shared via:

There aren’t any published security advisories