Skip to content

Security: mehmet-kozan/pdf-parse

.github/SECURITY.md

Security Policy

npm provenance npm audit socket badge snyk vulnerabilities

Package Provenance

This package is published with npm provenance enabled. Provenance provides transparency about where and how the package was built, helping you verify its authenticity.

You can verify the provenance of this package by:

  • Viewing the provenance attestation on the npm package page
  • Checking the build details linked from the npm registry

Security Scanning

Users are encouraged to scan this package for vulnerabilities using tools like:

  • npm audit - Built-in npm security auditing tool
  • Snyk - Comprehensive security scanning and monitoring
  • Socket.dev - Supply chain security and malicious code detection

Reporting Security Issues

To report a security vulnerability, please use the Tidelift security contact. Tidelift will coordinate the fix and disclosure.

To report a malicious npm package, please use npm's guide.

There aren’t any published security advisories