Skip to content

Security: M8T-Jacob/allegro-sdk

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.x ✅

Reporting a Vulnerability

@m8t-jacob/allegro-sdk has zero runtime dependencies — it uses the global fetch available in Node.js 20+ (or an injected implementation via AllegroClientConfig.fetch) to call the Allegro REST API (api.allegro.pl / api.allegro.pl.allegrosandbox.pl) and Allegro's OAuth server (allegro.pl / allegro.pl.allegrosandbox.pl). The attack surface is therefore limited to: URL and query-string construction from user-supplied input (category/offer/order ids, search phrases), the clientId/clientSecret pair (sent only as an Authorization: Basic base64(clientId:clientSecret) header on OAuth token requests, never in a URL or logged), and the Authorization: Bearer <token> header used for authenticated REST API calls (the token is never logged, and never appears in a URL).

If you discover a security vulnerability, please do not open a public issue. Instead, report it privately via GitHub Security Advisories for this repository.

Please include:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce (a minimal code sample is ideal)
  • The package version affected

We aim to acknowledge reports within 5 business days and to release a fix as soon as reasonably possible.

There aren't any published security advisories