generated: '2026-08-27' method: searched source: https://github.com/salesforce/lwc/blob/master/SECURITY.md provider: Lightning Web Components providerId: lightning-web-components description: >- Vulnerability disclosure posture for Lightning Web Components. The LWC project publishes its own SECURITY.md in the open-source repository naming a direct reporting address; the surrounding program (safe harbour, triage, bounty) is run by Salesforce, LWC's parent, and applies to LWC because SECURITY.md routes reports into it. disclosure: published: true policy_url: https://github.com/salesforce/lwc/blob/master/SECURITY.md policy_status: 200 contact_email: security@salesforce.com first_party: true statement: >- "Please report any security issue to security@salesforce.com as soon as it is discovered. This library limits its runtime dependencies in order to reduce the total cost of ownership as much as can be, but all consumers should remain vigilant and have their security stakeholders review all third-party products (3PP) like this one and their dependencies." security_txt: served: false note: >- No RFC 9116 /.well-known/security.txt is served on lwc.dev (HTTP 500 catch-all), developer.salesforce.com (HTTP 403 bot challenge) or www.salesforce.com (HTTP 404). The disclosure contact is published in the repository SECURITY.md instead. program: scope: parent-brand name: Salesforce Responsible Disclosure / Bug Bounty disclosure_page: https://www.salesforce.com/company/disclosure/ disclosure_page_status: 200 security_site: https://security.salesforce.com/ security_site_status: 200 bug_bounty: platform: HackerOne url: https://hackerone.com/salesforce status: 200 invite_only: true note: >- Salesforce operates an invitation-based bug bounty; researchers submit suspected vulnerabilities via Hackforce and track progress there. Salesforce publicly reports having paid out over $18.9M across roughly 30,600 reported potential vulnerabilities. safe_harbor: published: true statement: >- "Salesforce pledges not to initiate legal action against researchers for penetrating or attempting to penetrate our systems as long as they adhere to this policy." researcher_recognition: https://security.salesforce.com/security-research-contributors/ supply_chain: dependabot: true dependabot_evidence: .github/dependabot.yml present in salesforce/lwc note: >- Dependency bumps appear as first-class entries in the LWC release stream (js-yaml, vite, postcss, fast-xml-parser, systeminformation across v9.3.4–v9.4.0), which is the visible output of that automation. maintainers: - FN: Kin Lane email: kin@apievangelist.com