Please do not report security vulnerabilities through public GitHub issues.
Instead, report them privately via either:
- GitHub Security Advisories — go to the Security tab and click Report a vulnerability. (Preferred.)
- Email codlibs.io@gmail.com with the subject line
stream-gatherers security.
Please include:
- A description of the issue and its impact
- Steps to reproduce or a proof-of-concept
- The version of
stream-gatherersaffected - Any suggested mitigation, if you have one
We'll acknowledge your report within 7 days and aim to publish a fix or workaround within 30 days for confirmed issues. You'll be credited in the release notes unless you ask not to be.
Only the latest minor release receives security fixes. Older versions may receive patches at our discretion.