Security fixes are generally applied to the latest published version of nest-can-react. Users should upgrade to the latest release when possible.
Please do not report security vulnerabilities through a public GitHub issue.
Use GitHub’s private vulnerability reporting form. Include:
- A description of the vulnerability and its potential impact.
- The affected versions and package configuration.
- Reproduction steps or a proof of concept, if available.
- Any suggested mitigation.
Please allow maintainers reasonable time to investigate and prepare a fix before publicly disclosing the issue. We will acknowledge valid reports, keep the reporter informed when possible, and credit reporters in the release notes unless they prefer to remain anonymous.
If private vulnerability reporting is unavailable, contact the repository maintainers privately through GitHub rather than opening a public issue.