Only the latest published npm release is security-supported.
| Version | Supported |
|---|---|
| latest | ✔️ |
| older | ❌ |
Please report security issues privately using GitHub Security Advisories.
You can expect an acknowledgement within 72 hours. Once a fix is available, a patched version will be published to npm and the vulnerability will be disclosed responsibly after it has been resolved.
Dependencies are checked on a regular schedule (pnpm audit). If a vulnerable dependency cannot be patched within the supported range, it will be reported as a security advisory until an upstream fix is available.