Only the latest minor release of pdfmonkey receives security updates.
If you discover a security vulnerability in this SDK, please do not open a public GitHub issue.
Instead, email tinymonkey@pdfmonkey.io with:
- A description of the issue and its impact.
- Reproduction steps or a proof-of-concept.
- The version of the SDK affected.
- Your name or handle for credit (optional).
We aim to acknowledge reports within 2 business days and to provide a remediation timeline within 7 business days. Please allow us reasonable time to investigate and ship a fix before any public disclosure.
This policy covers the pdfmonkey Node.js SDK only. For vulnerabilities
in the PDFMonkey API, dashboard, or rendering engines, please use the same
contact address with the appropriate context.