openapi-chain

Security

Report suspected vulnerabilities through GitHub private vulnerability reporting. Include the package version, affected entry point, a minimal synthetic OpenAPI example, expected/actual behavior, and whether the issue occurs with native Fetch. Do not include production credentials, tokens, customer data, or private schemas.

Private vulnerability reporting is enabled for this repository. The reporting form requires GitHub authentication. If the form is temporarily unavailable, open an issue titled “Private security reporting channel requested” with no vulnerability details so a maintainer can restore the private channel. Do not publish an exploit or sensitive reproduction in the issue.

Maintainers must keep Settings → Advanced Security → Private vulnerability reporting enabled and check the channel before a stable release. The repository setting is managed separately from this file. See GitHub's configuration guide. This project does not promise a response-time SLA.