Please report suspected vulnerabilities privately by emailing security@pkgstory.dev or using GitHub's private vulnerability reporting. Do not open a public issue for an undisclosed vulnerability.
Include the affected component, version, or commit; reproduction steps; potential impact; and any suggested mitigation. We will acknowledge the report, investigate it, and coordinate disclosure with you.
pkgstory is a continuously deployed service. Security fixes are applied to the current deployment; older revisions are not supported.