Skip to content

Security: prerender/prerender-node

Security

SECURITY.md

Security Policy

Supported Versions

We actively support the following versions of prerender-node with security updates:

Version Supported
3.8.x
3.7.x
< 3.7

Reporting a Vulnerability

We take security vulnerabilities seriously. If you discover a security vulnerability in prerender-node, please report it privately.

How to Report

Please do not report security vulnerabilities through public GitHub issues.

Instead, please report vulnerabilities by:

  1. Email: Send details to [email protected]
  2. GitHub Security: Use GitHub's private vulnerability reporting feature

What to Include

Please include the following information in your report:

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Affected versions
  • Potential impact
  • Any suggested fixes (if available)

Response Timeline

  • Initial Response: We aim to acknowledge receipt within 24-48 hours
  • Status Update: We will provide regular updates on our investigation
  • Resolution: We will work to resolve confirmed vulnerabilities as quickly as possible

Responsible Disclosure

We kindly ask that you:

  • Give us reasonable time to investigate and fix the vulnerability
  • Do not publicly disclose the vulnerability until we have released a fix
  • Do not exploit the vulnerability or access data beyond what is necessary to demonstrate the issue

Security Updates

Security updates are released as patch versions and announced through:

  • GitHub releases
  • npm advisory database
  • Security advisories on this repository

Thank you for helping keep prerender-node secure!

There aren’t any published security advisories