Only the latest version of each project is supported with security updates.
If you discover a security vulnerability, please report it responsibly:
- Do not open a public issue
- Email security concerns to the repository owner
- Include steps to reproduce and potential impact
All repositories in this account enforce:
ignore-scripts=truein.npmrc— blocks postinstall-based attacks- Dependabot — weekly automated dependency updates
npm ciin all CI/CD pipelines — deterministic installs from lock files- Socket.dev monitoring (where enabled) — flags malicious packages