While this package is in its 0.x line, security fixes are released against the latest minor version only.
| Version | Supported |
|---|---|
0.x (latest) |
✅ |
| older | ❌ |
Please do not open a public issue for security vulnerabilities.
Report them privately through GitHub's private vulnerability reporting (the "Report a vulnerability" button on the repository's Security tab). Include:
- a description of the vulnerability and its impact,
- the steps to reproduce it,
- the affected version(s),
- and, if possible, a suggested fix.
You can expect an acknowledgment within 3 business days and an assessment of the report, including a remediation timeline, within 10 business days. We will keep you informed throughout and credit you in the release notes once a fix ships, unless you prefer to remain anonymous.
Dependencies are kept current automatically: Renovate opens the update pull requests, and GitHub's Dependabot alerts flag known advisories — which Renovate turns into prioritized security updates. Every update is reviewed before it is merged.