This project follows Semantic Versioning.
Security fixes are provided for:
- The latest published
1.xversion
If you are using an older version, please upgrade to the latest release.
Please do not open public issues for security vulnerabilities.
Instead, use one of the following:
-
GitHub Security Advisories (preferred)
- Go to the repository page → Security → Advisories → Report a vulnerability
-
Email (fallback)
- Contact the maintainer via the email address listed on the npm package / GitHub profile.
In your report, include as much detail as possible:
- A clear description of the vulnerability
- Steps to reproduce (PoC if possible)
- Affected versions
- Any relevant logs, screenshots, or stack traces
- You’ll receive an acknowledgement as soon as practical.
- We’ll investigate and, if confirmed, publish a fix and release notes.
- We’ll coordinate a disclosure timeline when appropriate.