Report vulnerabilities through GitHub private vulnerability reporting. Do not publish exploit details, credentials, repository contents, or unredacted command output in an issue.
The project is pre-release. Security fixes target main and the most recent npm prerelease after publishing begins.