Only the latest published version on npm receives security fixes.
| Version | Supported |
|---|---|
| latest | ✅ |
| older | ❌ |
Please do not open a public issue for security vulnerabilities.
- Preferred: use GitHub private vulnerability reporting to file a private advisory.
- Include: affected version, a description of the issue, steps to reproduce, and potential impact.
We will acknowledge reports within 72 hours and aim to ship a fix (or a mitigation note) within 7 days of confirmation. Once a fix is released we will credit the reporter in the release notes unless they prefer to remain anonymous.