doc: clarify threat model for application-level API exposure · nodejs/node@f418fcc · GitHub
Skip to content

Commit f418fcc

Browse files
committed
doc: clarify threat model for application-level API exposure
Add examples of non-vulnerabilities when applications expose Node.js APIs to untrusted users without proper security boundaries. PR-URL: #61184 Reviewed-By: Aviv Keller <me@aviv.sh> Reviewed-By: Chengzhong Wu <legendecas@gmail.com> Reviewed-By: Matteo Collina <matteo.collina@gmail.com> Reviewed-By: Gireesh Punathil <gpunathi@in.ibm.com> Reviewed-By: Colin Ihrig <cjihrig@gmail.com> Reviewed-By: Luigi Pinca <luigipinca@gmail.com> Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
1 parent 1186108 commit f418fcc

1 file changed

Lines changed: 26 additions & 0 deletions

File tree

SECURITY.md

Lines changed: 26 additions & 0 deletions

0 commit comments

Comments
 (0)