Email security@nodemaven.com with:
- the repository and version affected
- what an attacker can do with it
- steps to reproduce, ideally a minimal case
Please do not open a public issue for security problems, and please do not include working credentials in the report.
We aim to acknowledge within two business days.
In scope: the code in repositories under this organization.
Out of scope for this address: problems with the NodeMaven service or your account. Those go to support@nodemaven.com.
If you find a credential committed to any repository here - ours or a contributor's - treat it as a vulnerability and report it the same way. Assume anything that reached a public commit is compromised, even if it was removed afterwards.