Security fixes are prioritized for:
- Latest main branch
- Most recent published package versions across active registries
Older versions may not receive security updates.
Please do not open public issues for security vulnerabilities.
Use one of these options:
- GitHub private vulnerability report (preferred)
- Direct maintainer contact listed in repository profile
Please include:
- A clear description of the issue
- Impact and affected components
- Reproduction steps or proof of concept
- Suggested remediation (if available)
- Initial acknowledgment: within 72 hours
- Triage and impact assessment: as soon as possible
- Fix and disclosure coordination: based on severity and ecosystem impact