Only the latest major version of each published package receives security updates. Older versions are not patched retroactively.
To report a security vulnerability, please email darshankachare@email.com. Do not open a public GitHub issue.
You will receive a response within 48 hours. If the issue is confirmed, a patch will be prepared and released as soon as possible, typically within 7 days.
- The vulnerability is reported privately to the maintainers
- A fix is developed and tested
- The fix is released as a patch version update
- The vulnerability is publicly disclosed after the fix is available
This process ensures that users can update before details of the vulnerability are made public.