Report a vulnerability in the Node/TypeScript SDK privately, through GitHub's private vulnerability reporting: the Report a vulnerability button on this repository's Security tab. Please do not open a public issue or pull request for it.
Include what you found, how to reproduce it, and what an attacker could do with it. We will acknowledge the report, keep you informed while we investigate, and credit you in the fix unless you ask us not to.
This repository covers the Node/TypeScript SDK: how the client handles API keys, requests and responses. The Lenz API itself and the lenz.io site are out of scope here; report issues with them the same way and we will route them.
Fixes land on main and ship in the next release. Older releases are not
patched.