Skip to content

Security: nhankyjangchan/koa-cors

.github/SECURITY.md

Security Policy

Maintaining the security of @nhankyjangchan/koa-cors is essential to protecting its users and the continued development of this package. If you discover a vulnerability, your responsible disclosure is appreciated and will be addressed promptly.

ℹ️ Note: Starting with v1.4.0, this package has been migrated to a new name: @nhankyjangchan/koa-cors. If you're still using legacy @nhankyjangchan/koajs-cors, please migrate to new package — it is now deprecated and receives security fixes only. Migration is seamless, just install the new package and swap the package name in your package.json and import statements. The API remains unchanged.

📦 Supported Versions

The latest minor version receives active maintenance. The previous minor version receives security fixes only. Older versions are no longer supported.

Version Supported Notes
2.1.x Active maintenance
2.0.x No longer supported
1.4.x Security fixes only
1.3.x No longer supported
1.2.x No longer supported
1.1.x No longer supported
1.0.x No longer supported

🔒 Reporting a Vulnerability

Please DO NOT report security vulnerabilities through public GitHub issues, discussions, pull requests, or any other public channel. Doing so exposes the vulnerability to potential attackers before a fix can be prepared and released, endangering all users who depend on this package.

📧 Where to report

Send an email to dev.schuchkin.timur@gmail.com or write to me directly on Telegram with the following details:

  • Package version where the vulnerability was found
  • Affected configuration (if applicable)
  • Step-by-step instructions to reproduce the issue
  • Impact — what an attacker could potentially do
  • Suggested fix (optional, but appreciated)

⏱️ What to expect

Step Timeframe Description
1 Within 72 hours Initial response confirming receipt
2 Within 7 days Triage and severity assessment
3 Within 14 days Fix prepared (or decision to release with next regular update)
4 Upon release Public disclosure with credits

📢 Disclosure Policy

  • A new patch version will be released as soon as a fix is ready
  • The vulnerability will be publicly disclosed in the release notes
  • You will be credited (unless you wish to remain anonymous)

⭐ Recognition

Thank you to everyone who has helped improve the security of this package. Contributors will be acknowledged here.

Contributor Vulnerability Date

Will be updated as contributions are received.


💙 Thanks for helping improve this plugin!

There aren't any published security advisories