Skip to content

Security: openfetch-js/OpenFetch

Security

.github/SECURITY.md

Security policy

The full threat model, SSRF/cache/retry guidance, and local security checks live in SECURITY.md at the repository root (also shipped on npm).

Reporting a vulnerability

Please do not open a public issue for undisclosed security defects.

Include enough detail to reproduce or reason about impact. We aim to acknowledge valid reports and coordinate disclosure after a fix is available.

There aren’t any published security advisories