You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The full threat model, SSRF/cache/retry guidance, and local security checks live in [`SECURITY.md`](../SECURITY.md) at the repository root (also shipped on npm).
4
+
5
+
## Reporting a vulnerability
6
+
7
+
Please do **not** open a public issue for undisclosed security defects.
8
+
9
+
- Prefer a [GitHub private security advisory](https://github.com/openfetch-js/OpenFetch/security/advisories/new) for this repository, or
10
+
- Contact the maintainer privately if you cannot use GitHub advisories.
11
+
12
+
Include enough detail to reproduce or reason about impact. We aim to acknowledge valid reports and coordinate disclosure after a fix is available.
0 commit comments