Report vulnerabilities through the repository's private security advisory form. Do not post exploit details in a public issue.
Include the affected version, a minimal reproduction, expected and observed behavior, and likely impact. Disclosure timing will be coordinated after validation.
Before 1.0, only the latest pre-release candidate is eligible for fixes. Historical registry artifacts remain available for reproducibility, not ongoing support.
Actions and installer versions are pinned, versioned registry artifacts are append-only, package candidates include checksums and an SBOM, and npm publication remains disabled while the package is private.