Skip to content

Security: vercel-labs/error

Security

SECURITY.md

Security

This package's core guarantee is disclosure control: developer-facing error details must never reach a client response unless explicitly approved under public. Treat any violation of that guarantee as a security vulnerability, not an ordinary bug.

Report vulnerabilities privately through Vercel's bug bounty program for open source projects: https://hackerone.com/vercel-open-source. Do not open a public GitHub issue for a security report.

There aren't any published security advisories