json-ty is currently an early 0.0.0 preview installed from GitHub. Security
fixes are applied to the latest main revision; older commits are not supported
as separate release lines.
Please do not open a public issue for a vulnerability that could put users or their data at risk.
Email me@jairus.dev with:
- a minimal reproduction or malformed input;
- affected commit and Node version;
- expected and observed behavior;
- potential impact;
- any suggested fix or mitigation.
Reports will be acknowledged as soon as practical and handled privately until a fix or coordinated disclosure plan is ready. Credit will be given with the reporter's permission.
Memory-safety, stale-view, allocator, parser-boundary, generated-code injection, and malicious-schema issues are especially valuable to report.