Skip to content

安全: nodejs/nodejs.org

SECURITY.md

安全

Reporting a vulnerability to Node.js Website

Please report security issues privately using the GitHub 安全 Advisory workflow (安全 → “Report a vulnerability”).

Do not open a public GitHub issue for security problems.

We aim to acknowledge reports within 7 business days. If you do not receive an acknowledgement within 7 business days, forward your report to tsc@nodejs.org.

Disclosure & advisories

Confirmed vulnerabilities will be published as a GitHub 安全 Advisory (and assigned a CVE when applicable). Notices are also shared via:

There aren't any published security advisories