mirror of
https://github.com/nlohmann/json.git
synced 2026-10-04 05:30:31 +00:00
31 lines
2.3 KiB
Markdown
31 lines
2.3 KiB
Markdown
# Security Policy
|
|
|
|
## Reporting a Vulnerability
|
|
|
|
We value the security of our users and appreciate your efforts to responsibly disclose vulnerabilities. If you have identified a security vulnerability in this repository, please use the GitHub Security Advisory ["Report a Vulnerability"](https://github.com/nlohmann/json/security/advisories/new) tab.
|
|
|
|
Until it is published, this draft security advisory will only be visible to the maintainers of this project. Other users and teams may be added once the advisory is created.
|
|
|
|
We will send a first response within 14 days, indicating the next steps in handling your report. After the initial reply to your report, we will keep you informed of the progress towards a fix and full announcement and may ask for additional information or guidance.
|
|
|
|
For vulnerabilities in third-party dependencies or modules, please report them directly to the respective maintainers.
|
|
|
|
## Disclosure and credit
|
|
|
|
Once a fix is released, we publish the security advisory and list the fixed vulnerability in the release notes. We credit the reporter in both, unless they ask not to be named.
|
|
|
|
## Supported versions
|
|
|
|
Security fixes are made on the `develop` branch and shipped with the next release. Only the latest release receives security fixes; they are not backported to older releases. A release stops receiving security fixes when the next release is published, so please update to the latest release to get them.
|
|
|
|
## Unofficial packages
|
|
|
|
This project does not publish an official npm package. The npm package [`nlohmann-json`](https://www.npmjs.com/package/nlohmann-json) (or similarly named packages) is not maintained or endorsed by this project. See the [package managers documentation](https://json.nlohmann.me/integration/package_managers/#npm) for supported integration options.
|
|
|
|
## Additional Resources
|
|
|
|
- Explore security-related topics and contribute to tools and projects through [GitHub Security Lab](https://securitylab.github.com/).
|
|
- Learn more about responsible disclosure and reporting vulnerabilities in GitHub at [About coordinated disclosure of security vulnerabilities](https://docs.github.com/en/code-security/repository-security-advisories/about-coordinated-disclosure-of-security-vulnerabilities).
|
|
|
|
We sincerely thank you for contributing to the security and integrity of this project!
|