three-iges-loader

Security policy

Supported versions

Version Supported
Latest on npm
Older major/minor ❌ (upgrade recommended)

Reporting a vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

  1. Use GitHub private vulnerability reporting if enabled, or
  2. Email the maintainers via the contact on the npm package page / repository owner profile.

Include:

We aim to acknowledge within 5 business days and release a fix or advisory when appropriate.

Scope notes

This library parses text IGES files in user-controlled environments. Threat model includes:

Not in scope: vulnerabilities in Three.js or your application code that merely uses this loader.