We actively support both the 2.x and 1.x release lines. Security fixes land in the latest patch release of each line, so upgrading within your major version is enough to receive them.
| Release line | npm dist-tag | Supported |
|---|---|---|
| 2.x | latest |
✅ Supported |
| 1.x | legacy |
✅ Supported |
| Pre-releases | next |
Versions below 1.0 are no longer supported.
If you believe you’ve found a security issue in SuperDoc, please do not open a public GitHub issue.
Instead, report it privately through GitHub’s Security Advisories.
This ensures the report is only visible to maintainers.
If you prefer email, you can also contact us at: q@superdoc.dev
- We will acknowledge receipt within 2 business days.
- We will provide a status update within 7 days.
- Once a fix is available, we’ll coordinate a responsible disclosure with you.
Thank you for helping keep SuperDoc and its users safe!