If you find a security vulnerability in cairn, please report it privately. Do not open a public issue.
Email the maintainers, or open a private security advisory on GitHub:
https://github.com/cairnjs/cairn/security/advisories/new
Please include:
- A description of the vulnerability
- Steps to reproduce, or a minimal proof of concept
- Impact what an attacker could do
We'll acknowledge the report and work on a fix. We'll coordinate disclosure once a fix is released.
This applies to the @cairnjs/* packages. The example apps are for demonstration and are not covered.