| Version | Supported |
|---|---|
| 2.x | ✅ |
| 1.x | ❌ |
Please report security issues privately through GitHub Security Advisories, not as a public issue.
Expect an acknowledgement within a few days. This is a single-maintainer package, so please allow reasonable time for a fix before disclosing publicly.
This package is a Stylelint configuration — it ships no executable code beyond a plain config object, and it runs only in a developer's or CI environment, never in production. The realistic attack surface is its dependency tree. Dependency updates are automated via Dependabot, and releases are published to npm with provenance attestation.