Report potential vulnerabilities privately through this repository's GitHub Security Advisories page using Private Vulnerability Reporting. Do not open a public issue, pull request, or discussion for an unpatched vulnerability.
Before 1.0.0, only the latest published version receives security fixes.
Latest verified published version: 0.2.3. The support table follows verified npm publication, not source version changes alone.
| Version | Supported |
|---|---|
| 0.2.3 | Yes |
| < 0.2.3 | No |
Keep Private Vulnerability Reporting active and enable GitHub's available dependency and secret-scanning alerts. Bootstrap the brand-new npm package interactively with maintainer 2FA and no automation token because trusted and staged publishing require an existing package.
After bootstrap, register the exact repository, publish.yml, and npm environment as the trusted publisher. Allow only npm stage publish, disallow token publishing, and require maintainer 2FA approval for every staged version.
The maintainer will assess the report, prepare a remediation when applicable, and decide whether to publish a GitHub security advisory or request a CVE after the remediation is available.
Treat a credential/PII incident as a release blocker. Stop the affected release, rotate any exposed credential, preserve non-public evidence, and coordinate remediation without public disclosure of the sensitive value.