Please report suspected vulnerabilities privately through GitHub's Security > Report a vulnerability flow for this repository. Do not open a public issue or discussion for a suspected vulnerability.
Include the affected package or Go module version, a minimal reproduction, the expected impact, and any suggested mitigation. The maintainers will acknowledge the report and coordinate disclosure after a fix is available.
Security fixes are applied to the latest published npm packages and the latest Go module release. Older releases may require upgrading to receive a fix.