Please do not open a public issue for security vulnerabilities.
Report privately through GitHub's private vulnerability reporting:
Repository → Security tab → Report a vulnerability
This opens a private advisory visible only to you and the maintainers. We aim to acknowledge reports within a few business days and will keep you updated on remediation and disclosure timing.
Please include:
- the affected package and version,
- a description of the issue and its impact,
- a minimal reproduction or proof of concept, if possible.
While these packages are pre-1.0, only the latest published version of each package receives security fixes.
This policy covers the packages published from this repository. It does not cover the private ƒxyz network services, which are out of scope here.