Security fixes are applied to the latest released 1.x line. Older 0.x pre-release
versions are no longer supported — please upgrade to the current release on
npm.
| Version | Supported |
|---|---|
| 1.x | ✅ |
| 0.x | ❌ |
In order for the vulnerability reports to reach maintainers as soon as possible, the preferred way is to use the "Report a vulnerability" button under the "Security" tab of the associated GitHub project. This creates a private communication channel between the reporter and the maintainers.
If you are absolutely unable to or have strong reasons not to use GitHub's vulnerability reporting workflow, please reach out to saul.ivan.rivas.vega@gmail.com.