Skip to content

Security: loopbackio/loopback-next

SECURITY.md

Security Policy

Supported Versions

LoopBack implements the Module LTS policy.

Version Supported
LoopBack 4
LoopBack 3
LoopBack 2
Supported connectors

Database connectors

Other connectors

Within LoopBack 4, fixes are not backported across semver major versions of a package.

Security advisories

Security advisories can be found on the LoopBack website.

Reporting a vulnerability

If you think you have discovered a new security issue with any LoopBack package, please do not report it on GitHub. Instead, send an email to [email protected] with the following details:

  • Full description of the vulnerability.
  • Steps to reproduce the issue.
  • Possible solutions.

If you are sending us any logs as part of the report, then make sure to redact any sensitive data from them.

Escalation

If you do not receive an acknowledgement of your report within 6 business days, or if you cannot find a private security contact for the project, you may escalate to the OpenJS Foundation CNA at [email protected].

If the project acknowledges your report but does not provide any further response or engagement within 14 days, escalation is also appropriate.

There aren’t any published security advisories