Maintaining the security of @nhankyjangchan/koa-cors is essential to protecting its users and the continued development of this package. If you discover a vulnerability, your responsible disclosure is appreciated and will be addressed promptly.
ℹ️ Note: Starting with v1.4.0, this package has been migrated to a new name: @nhankyjangchan/koa-cors. If you're still using legacy @nhankyjangchan/koajs-cors, please migrate to new package — it is now deprecated and receives security fixes only. Migration is seamless, just install the new package and swap the package name in your
package.jsonand import statements. The API remains unchanged.
The latest minor version receives active maintenance. The previous minor version receives security fixes only. Older versions are no longer supported.
| Version | Supported | Notes |
|---|---|---|
| 2.1.x | ✅ | Active maintenance |
| 2.0.x | ❌ | No longer supported |
| 1.4.x | ✅ | Security fixes only |
| 1.3.x | ❌ | No longer supported |
| 1.2.x | ❌ | No longer supported |
| 1.1.x | ❌ | No longer supported |
| 1.0.x | ❌ | No longer supported |
Please DO NOT report security vulnerabilities through public GitHub issues, discussions, pull requests, or any other public channel. Doing so exposes the vulnerability to potential attackers before a fix can be prepared and released, endangering all users who depend on this package.
Send an email to dev.schuchkin.timur@gmail.com or write to me directly on Telegram with the following details:
- Package version where the vulnerability was found
- Affected configuration (if applicable)
- Step-by-step instructions to reproduce the issue
- Impact — what an attacker could potentially do
- Suggested fix (optional, but appreciated)
| Step | Timeframe | Description |
|---|---|---|
| 1 | Within 72 hours | Initial response confirming receipt |
| 2 | Within 7 days | Triage and severity assessment |
| 3 | Within 14 days | Fix prepared (or decision to release with next regular update) |
| 4 | Upon release | Public disclosure with credits |
- A new patch version will be released as soon as a fix is ready
- The vulnerability will be publicly disclosed in the release notes
- You will be credited (unless you wish to remain anonymous)
Thank you to everyone who has helped improve the security of this package. Contributors will be acknowledged here.
| Contributor | Vulnerability | Date |
|---|---|---|
| — | — | — |
Will be updated as contributions are received.
💙 Thanks for helping improve this plugin!