| Version | Supported |
|---|---|
| 0.x | ✅ |
@m8t-jacob/allegro-sdk has zero runtime dependencies — it uses the global
fetch available in Node.js 20+ (or an injected implementation via
AllegroClientConfig.fetch) to call the Allegro REST API
(api.allegro.pl / api.allegro.pl.allegrosandbox.pl) and Allegro's OAuth
server (allegro.pl / allegro.pl.allegrosandbox.pl). The attack surface is
therefore limited to: URL and query-string construction from user-supplied
input (category/offer/order ids, search phrases), the
clientId/clientSecret pair (sent only as an
Authorization: Basic base64(clientId:clientSecret) header on OAuth token
requests, never in a URL or logged), and the Authorization: Bearer <token>
header used for authenticated REST API calls (the token is never logged, and
never appears in a URL).
If you discover a security vulnerability, please do not open a public issue. Instead, report it privately via GitHub Security Advisories for this repository.
Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce (a minimal code sample is ideal)
- The package version affected
We aim to acknowledge reports within 5 business days and to release a fix as soon as reasonably possible.