UNPKG

1.2 kBMarkdownView Raw
1# Security Policies and Procedures
2
3## Reporting a Bug
4
5The `finalhandler` team and community take all security bugs seriously. Thank
6you for improving the security of Express. We appreciate your efforts and
7responsible disclosure and will make every effort to acknowledge your
8contributions.
9
10Report security bugs by emailing the current owner(s) of `finalhandler`. This
11information can be found in the npm registry using the command
12`npm owner ls finalhandler`.
13If unsure or unable to get the information from the above, open an issue
14in the [project issue tracker](https://github.com/pillarjs/finalhandler/issues)
15asking for the current contact information.
16
17To ensure the timely response to your report, please ensure that the entirety
18of the report is contained within the email body and not solely behind a web
19link or an attachment.
20
21At least one owner will acknowledge your email within 48 hours, and will send a
22more detailed response within 48 hours indicating the next steps in handling
23your report. After the initial reply to your report, the owners will
24endeavor to keep you informed of the progress towards a fix and full
25announcement, and may ask for additional information or guidance.