jpg619/fix-accessibility-content-flow
@reggi/path-to-regexp
dependabot/npm_and_yarn/main/copy-to-clipboard-4.0.2
dependabot/npm_and_yarn/main/eslint-10.4.0
dependabot/npm_and_yarn/main/npmcli/eslint-config-7.0.0
dependabot/npm_and_yarn/main/proc-log-7.0.0
dependabot/npm_and_yarn/npm_and_yarn-826852524d
dependabot/npm_and_yarn/npm_and_yarn-ab9a7f4bc2
deprecate-totp-2fa
dhei/classic-tokens
gat-bypass-2fa-docs
jpg619/fix-accessibility-content-flow
jpg619/version-bump-tar-2
kartykp/gat-bypass-2fa-docs
kartykp/upgrade-path-to-regex
main
maitxn/version-bump-tar
patch-1
reggi/cache-based-on-version
reggi/dev-engines
reggi/fix-transform-prettier
reggi/overrides
update-search-sensitivity
| 1 | --- |
| 2 | title: npm Security Policy |
| 3 | edit_on_github: false |
| 4 | --- |
| 5 | |
| 6 | Outlined in this document are the practices and policies that npm applies to help ensure that we release stable/secure software, and react appropriately to security threats when they arise. |
| 7 | |
| 8 | ## Table of Contents |
| 9 | |
| 10 | 1. [Reporting Security Problems to npm](#reporting-security-problems-to-npm) |
| 11 | 1. [Security Point of Contact](#security-point-of-contact) |
| 12 | 1. [Critical Updates And Security Notices](#critical-updates-and-security-notices) |
| 13 | |
| 14 | ## Reporting Security Problems to npm |
| 15 | |
| 16 | If you need to report a security vulnerability. Please visit [https://npmjs.com/support](https://npmjs.com/support). If your issue is specific to your account, such as lost credentials or problems with two-factor authentication, contacting [our support team](https://npmjs.com/support) is more appropriate. |
| 17 | |
| 18 | We review all security reports on the next business day. Note that the npm staff is generally offline for most US holidays, but please do not delay your report! Our off-hours support staff can fix many issues, and will alert our security point of contact if needed. |
| 19 | |
| 20 | ## Security Point of Contact |
| 21 | |
| 22 | Any security tickets opened using [https://npmjs.com/support](https://npmjs.com/support) will be escalated to the security point of contact, who will delegate incident response activities as appropriate. This is the best and fastest way to contact npm about any security-related matter. |
| 23 | |
| 24 | ## Critical Updates And Security Notices |
| 25 | |
| 26 | We learn about critical software updates and security threats from a variety of sources: |
| 27 | |
| 28 | - Ubuntu's security notices page: [https://usn.ubuntu.com/](https://usn.ubuntu.com/) |
| 29 | - The Node.js mailing list. |
| 30 | - [Security tickets](https://npmjs.com/support) sent to us. |
| 31 | - and other media sources. |
| 32 | |
| 33 | ## Changes |
| 34 | |
| 35 | This is a living document and may be updated from time to time. Please refer to the [git history for this document](https://github.com/npm/documentation/blob/main/content/policies/security.mdx) to view the changes. |
| 36 | |
| 37 | ## License |
| 38 | |
| 39 | This document may be reused under a [Creative Commons Attribution-ShareAlike License](https://creativecommons.org/licenses/by-sa/4.0/). |