Please report security issues privately — do not open a public issue.
- GitHub: use private vulnerability reporting on this repository.
You should receive an acknowledgement within 72 hours. Please include a minimal reproduction and the affected package(s) and version(s).
Capix is pre-1.0. Only the latest published release receives security fixes — older alphas/betas are not patched retroactively. Once 1.0 ships, the latest minor of each supported major will receive fixes.
- The REST, WebSocket, GraphQL, and MCP transports are designed to face untrusted input; hardening issues there (parser crashes, resource exhaustion, validation bypasses, prototype pollution) are in scope and prioritized.
withRateLimit's in-memory default is per-process by design — see the enhancers guide for the distributed store. Reports that in-memory limits don't hold across instances are expected behavior, not vulnerabilities.- npm packages are published with provenance attestations; verify with
npm audit signatures.