Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Security: lodash/lodash

SECURITY.md

Supported versions

The following table describes the versions of this project that are currentlysupported with security updates:

VersionSupported
4.x
3.x
2.x
1.x

Threat Model

To better understand which classes of vulnerabilities are considered in-scope or out-of-scope for Lodash, please review theLodash Threat Model.

The threat model defines Lodash’s trust boundaries and clarifies how security issues are assessed for triage and disclosure.

Responsible disclosure security policy

A responsible disclosure policy helps protect users of the project from publiclydisclosed security vulnerabilities without a fix by employing a process wherevulnerabilities are first triaged in a private manner, and only publicly disclosedafter a reasonable time period that allows patching the vulnerability and providesan upgrade path for users.

We kindly ask you to refrain from malicious acts that put our users, the project,or any of the project’s team members at risk.

Reporting a security issue

We consider the security of Lodash a top priority. But no matter how much effortwe put into security, there can still be vulnerabilities present.

If you discover a security vulnerability, please report the security issuedirectly to the Lodash maintainers through theSecurity tab of the Lodashrepository.

Your efforts to responsibly disclose your findings are sincerely appreciated.

Escalation

If you do not receive an acknowledgement of your report within 6 business days, or if you cannot find a private security contact for the project, you may escalate to the OpenJS Foundation CNA atsecurity@lists.openjsf.org.

If the project acknowledges your report but does not provide any further response or engagement within 14 days, escalation is also appropriate.

There aren’t any published security advisories


[8]ページ先頭

©2009-2025 Movatter.jp