layn is pre-1.0. Security fixes are released against the latest published version of each @laynjs/* package. Please always upgrade to the latest release.
Do not report security vulnerabilities through public GitHub issues.
Instead, use GitHub's private vulnerability reporting:
- Go to the Security tab of the repository.
- Click "Report a vulnerability" and provide the details.
Please include:
- a description of the vulnerability and its impact,
- the affected package(s) and version(s),
- steps to reproduce or a proof of concept.
You will receive an acknowledgement, and we will work with you on a fix and a coordinated disclosure. Thank you for helping keep layn and its users safe.