Please do not open a public issue for a security vulnerability.
Every repository in this account has GitHub's private vulnerability reporting enabled. To use it:
- Go to the repository's Security tab.
- Click Report a vulnerability (top right of the Advisories section).
- Fill in the form and submit.
This opens a private draft security advisory shared only between you and the maintainer — nothing is public until you and the maintainer agree to publish it. It also gives you a private thread to discuss the issue, lets the maintainer request a CVE if one is warranted, and credits you as the reporter once the advisory is published.
This is the only channel for reporting a vulnerability in this account's repositories. There's no parallel email address for this — a second channel would only split reports across two places instead of keeping them in one.
This is a small, single-maintainer, open-source ecosystem. Reports are handled on a best-effort basis — there's no guaranteed response time or SLA. That said, security reports are prioritized over regular issues, and you'll get an acknowledgement as soon as reasonably possible.
This policy covers the packages published from kurkle's repositories (Chart.js chart
types and plugins, @kurkle/color, @kurkle/configs, @kurkle/astro-chartjs-editor).
It does not cover Chart.js itself — please report those separately to the
Chart.js project.