# Reporting Security Issues

Please report any security issues you discovered in the API to lucastesson@protonmail.com.

We will assess the risk, plus make a fix available before we create a GitHub issue.

In case the vulnerability is into a CVSS specification, do not report this to us but refer to [first.org](https://www.first.org/contact).

Thank you for your contribution.

## Refering to this repository

To refer to this repository using a CPE v2.3, please use `cpe:2.3:a:pandatix:js-cvss:*:*:*:*:*:*:*:*` with the `version` set to the tag you are using.
