Security updates are provided for the latest released version of each Superagent package. Please upgrade to the latest version before reporting an issue that may already have been fixed.
Please do not report security vulnerabilities through public GitHub issues, discussions, or Discord.
Report vulnerabilities privately through GitHub Security Advisories. Include, when possible:
- The affected package, version, and configuration
- A description of the vulnerability and its potential impact
- Reproduction steps or a minimal proof of concept
- Any known mitigations or suggested fixes
We will acknowledge the report as soon as possible, keep you informed while it is investigated, and coordinate disclosure after a fix is available. Please allow a reasonable amount of time for us to investigate and address the issue before publishing details.
This policy covers the code and packages maintained in this repository. For vulnerabilities in third-party dependencies, report the issue to the relevant maintainer as well as to us when it directly affects Superagent users.
Thank you for helping keep Superagent and its users safe.