| Version | Supported |
|---|---|
| 1.x | Yes |
| Upstream 0.x | No, maintained by its upstream owner |
Use GitHub's private vulnerability reporting for this repository. If that channel is unavailable, contact the maintainer through the security address on the Stackline organization profile.
Include the affected version and Node.js runtime, a minimal reproduction, expected impact, and any known workaround. Do not open a public issue before a coordinated fix is available.
We will acknowledge a complete report within five business days, investigate it privately, and coordinate disclosure and credit with the reporter. Normal Node stream validation, backpressure, and lifecycle behavior are compatibility questions unless they demonstrate a concrete security boundary violation.