# Node Supply Chain System โ€” https://github.com/ugixio (vendor: ugix.io) # # Coordinated vulnerability disclosure, ISO/IEC 29147:2018. # The policy this points at also states the safe harbour and our response times. # # THE URLS BELOW ARE PROMISES, AND ON 2026-09-02 ONE OF THEM WAS BROKEN. # `Policy:` pointed at qa.ugix.io, and QA went behind a credential on # 2026-09-01 โ€” so a researcher following this file reached a 401. The apex is # the public front door; the policy and the canonical location live there, with # the QA copy kept as a second Canonical because RFC 9116 allows more than one # and that URL has been published for months. # # This file is the SOURCE. It is published to the public surface only once the # contact mailbox is confirmed to deliver โ€” a contact address that silently # drops reports is worse than no contact address at all. See # docs/security/vulnerability-handling.md ยง5. Contact: mailto:security@ugix.io Expires: 2027-08-28T00:00:00.000Z Policy: https://ugix.io/security/vulnerability-disclosure.md Preferred-Languages: en, es Canonical: https://ugix.io/.well-known/security.txt Canonical: https://qa.ugix.io/.well-known/security.txt