Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,3 +11,12 @@

Vulnerabilities may be reported to [email protected]. Please include a description of the vulnerability and
steps to reproduce it. Suggested resolutions are also welcome.

## Escalation

If you do not receive an acknowledgement of your report within 6 business days, or if you
cannot find a private security contact for the project, you may escalate to the OpenJS Foundation CNA
at `[email protected]`.

If the project acknowledges your report but does not provide any further response or engagement within
14 days, escalation is also appropriate.