jsPsych is developed as a collection of npm packages under active development. Security fixes are made against the latest major version of each package (see the version listed on npmjs.com or in this repository's releases). Older major versions do not receive security patches.
Please do not report security vulnerabilities through public GitHub issues or discussions.
Instead, please report them using GitHub's private vulnerability reporting. If that option is not available to you, email jdeleeuw@vassar.edu with details of the vulnerability.
Please include as much of the following as you can, to help us triage your report:
- A description of the vulnerability and its potential impact
- Steps to reproduce, or a minimal example
- The affected package(s) and version(s)
We will acknowledge your report and aim to keep you updated as we investigate and address the issue.