As an OSS maintainer I take security bugs in my projects seriously.
If you believe you have found a vulnerability, please report it to me as described below.
Please do not report security vulnerabilities through public GitHub issues.
I appreciate your efforts to responsibly disclose your findings, and I will make every effort to acknowledge your contributions.
To report a security issue, email git_nikku AT nixis DOT de
and include the word "SECURITY" in the subject line.
I will send a response indicating the next steps in handling your report. After the initial reply to your report, I'll keep you informed of the progress towards a fix and full announcement, and may ask for additional information or guidance.
Report security bugs in third-party modules to the person or team maintaining the module. You can also report a vulnerability through the npm contact form by selecting "I'm reporting a security vulnerability".