If you discover a security vulnerability in any TaurusSoft repository, please do not open a public issue.
Instead, report it privately via one of the following:
- GitHub's private vulnerability reporting feature on the affected repository (Security tab → "Report a vulnerability")
- Email: info@taurussoftware.de
Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce (proof of concept if possible)
- The affected repository and version/commit
We aim to acknowledge reports within 5 business days and to provide a fix or mitigation plan within 30 days, depending on severity. Since these are community-maintained projects, timelines may vary.
Unless stated otherwise in a specific repository's README, only the latest published version on npm receives security fixes.
This applies to all repositories under the TaurusSoft organization, including n8n community nodes and any other published packages.