{
  "title": "README examples: handle a missing Authorization header",
  "category": "docs",
  "type": "docs",
  "severity": "info",
  "cvss": null,
  "ecosystem": "javascript",
  "project": {
    "owner": "jshttp",
    "repo": "basic-auth",
    "url": "https://github.com/jshttp/basic-auth"
  },
  "affected_versions": null,
  "status": "fixed",
  "disclosure": {
    "channel": "pr",
    "ghsa_id": null,
    "cve_id": null,
    "url": "https://github.com/jshttp/basic-auth/pull/108",
    "reported_at": "2026-10-07T11:57:32+03:00",
    "published_at": "2026-10-07T11:57:32+03:00"
  },
  "pr": {
    "url": "https://github.com/jshttp/basic-auth/pull/108",
    "state": "merged",
    "merged_at": "2026-10-08T02:28:27+03:00",
    "number": 108
  },
  "summary": "Docs-only PR: in v3, parse() expects a string, so the README examples now pass req.headers.authorization ?? '' to match the upgrade instructions. A request without an Authorization header then gets undefined back (and a 401 in the http server example). Merged.",
  "discovered_at": "2026-10-07T00:00:00+03:00",
  "public": true,
  "credit": "ucsurf",
  "updated_at": "2026-10-08T15:00:00+03:00",
  "id": "docs/javascript/jshttp__basic-auth/2026-10-07-readme-missing-authorization-header"
}
