Security fixes are made on the latest 0.4.x release line. Upgrade to the current npm latest version before reporting behavior that may already be fixed.
Report suspected vulnerabilities through GitHub private vulnerability reporting. Include the affected version, operating system and Node.js version, a minimal reproduction, expected impact, and any known mitigation.
Do not include access tokens, private repository contents, or other people's data. Do not open a public issue until the maintainer confirms that disclosure is safe. If GitHub private reporting is unavailable, open a public issue containing no exploit details and ask for a private contact channel.
The maintainer will acknowledge the report, validate its scope, coordinate a fix and release, and credit the reporter unless anonymity is requested. Response and release timing depends on severity and reproducibility; this document does not promise a fixed service-level deadline.