generated: '2026-09-05' method: searched probe: true source: https://github.com/cheeriojs/cheerio/blob/main/SECURITY.md note: >- probe-security-programs.py reported vdp=none because cheerio.js.org serves no /.well-known/security.txt and no /security page — the project publishes its policy in the repository instead, at SECURITY.md, which is where a Node.js library's consumers look. Fetched verbatim 2026-09-05 (HTTP 200 from raw.githubusercontent.com). policy: - https://github.com/cheeriojs/cheerio/blob/main/SECURITY.md - https://tidelift.com/security - https://github.com/cheeriojs/cheerio/security/advisories/new contact: - https://tidelift.com/security - https://github.com/cheeriojs/cheerio/security/advisories/new coordinator: Tidelift private_reporting: GitHub private vulnerability reporting (Security Advisories) public_issues_accepted: false supported_versions: - version: 1.x supported: true - version: '<1.0' supported: false note: Only the latest release on the 1.x branch receives security updates. sla: acknowledgment: 72 hours process: - Acknowledgment within 72 hours - Triage — severity, impact, affected versions - Fix and release a patch - Disclosure via a GitHub Security Advisory, crediting the reporter unless anonymity is requested in_scope: - Denial of service (ReDoS, quadratic parsing, excessive memory or CPU on crafted input) - Prototype pollution through parsed content or API misuse - Cross-site scripting enablement through unexpected serialization output - Supply chain — compromised dependencies, build pipeline or release artifacts - Information disclosure through parsing or serialization behavior out_of_scope: - Vulnerabilities in applications using cheerio caused by their own logic (e.g. not sanitizing cheerio output before rendering) - Social engineering attacks against maintainers related_documents: - https://github.com/cheeriojs/cheerio/blob/main/THREAT_MODEL.md - https://github.com/cheeriojs/cheerio/blob/main/INCIDENT_RESPONSE.md - https://cheerio.js.org/docs/advanced/security/ evidence: - source: https://raw.githubusercontent.com/cheeriojs/cheerio/main/SECURITY.md kind: security-policy http_status: 200 fetched: '2026-09-05' - source: https://raw.githubusercontent.com/cheeriojs/cheerio/main/THREAT_MODEL.md kind: threat-model http_status: 200 fetched: '2026-09-05' - source: https://raw.githubusercontent.com/cheeriojs/cheerio/main/INCIDENT_RESPONSE.md kind: incident-response-plan http_status: 200 fetched: '2026-09-05' - source: https://cheerio.js.org/.well-known/security.txt kind: security.txt http_status: 404 fetched: '2026-09-05' result: absent — policy is published in the repository instead maintainers: - FN: Kin Lane email: kin@apievangelist.com