Report vulnerabilities privately to security@pisama.ai with the affected package version, impact, and a minimal reproducer. Do not open a public issue for suspected security problems.
We will acknowledge reports within two business days and aim to provide a fix or mitigation within seven business days for confirmed high-severity issues.
Security fixes target the latest version published to npm. Reports about a
package archive should include the package name, version, dist.integrity
value from npm, and the result of npm audit signatures. Remove credentials,
project identifiers, prompts, completions, and trace content from reports
unless they are strictly required to reproduce the issue.