OPF is pre-1.0 software (see the Changelog). Only the latest published release of @openpresentation/opf on npm is supported with security fixes. We do not backport fixes to older 0.x releases.
Please do not open a public GitHub issue for security vulnerabilities.
Instead, report vulnerabilities privately using GitHub Security Advisories on the OpenPresentation/opf repository. This lets us assess and fix the issue before it is publicly disclosed.
Please include as much of the following as you can:
- A description of the vulnerability and its potential impact.
- Steps to reproduce, or a minimal example (e.g. a crafted
.opf.jsondocument or schema input). - The version of
@openpresentation/opfaffected.
This is a small open-source project maintained on a best-effort basis. We aim to acknowledge new reports within a reasonable timeframe and will keep you updated as we investigate and address confirmed issues. We ask for your patience and appreciate reports made in good faith.