Skip to content

Security: aurijs/jason

Security

SECURITY.md

Security Policy

Supported Versions

The following versions of Jason are currently being supported with security updates:

Version Supported
1.x.x
< 1.0.0

Reporting a Vulnerability

We take the security of Jason seriously. If you believe you've found a security vulnerability, please follow these steps:

Where to Report

  • Email: Send a detailed report to auri.js.dev@gmail.com
  • GitHub: For less sensitive issues, you can open a GitHub issue with the label "security" (please avoid including exploit details in public issues)

What to Include

  1. Description of the vulnerability
  2. Steps to reproduce the issue
  3. Affected versions
  4. Potential impact
  5. Any possible mitigations you've identified

Response Process

  1. You'll receive an acknowledgment of your report within 48 hours
  2. Our team will investigate and validate the issue
  3. We'll provide regular updates on our progress (at least weekly)
  4. Once resolved, we'll notify you and discuss appropriate disclosure

Disclosure Policy

  • We follow a coordinated disclosure process
  • Security issues will be addressed as quickly as possible
  • Public disclosure will be made after a patch is available and users have had reasonable time to update

Bug Bounty

We currently do not offer a formal bug bounty program, but we do acknowledge security researchers in our release notes with their permission.


Thank you for helping keep Jason and its users safe!

There aren’t any published security advisories