Security fixes are provided for the latest published version of each package.
Please use the repository's private Security > Report a vulnerability form instead of opening a public issue. Include the affected package and version, impact, reproduction steps, and any suggested mitigation.
Do not include npm tokens, model-provider credentials, Harness session logs, or other secrets in a report. Maintainers will acknowledge a complete report as soon as practical and coordinate disclosure after a fix is available.