Only the latest stable release receives security fixes.
Do not report security vulnerabilities through a public Issue.
Use GitHub's private security advisory feature for this repository and include:
- affected version and operating system
- selected project or global scope
- minimal reproduction steps
- files or paths affected
- expected and observed behavior
Do not include npm tokens, OpenAI credentials, private Codex configuration, or unrelated project source code.
Reports involving path escape, unsafe uninstall, transaction recovery, release provenance, or package publication are treated as security-sensitive.