Please report security issues privately through GitHub private vulnerability reporting.
Do not open a public issue for a vulnerability that has not been disclosed.
expect-fetch is a development-only assertion library with no production dependencies. Reports involving unsafe parsing, secret exposure in assertion output, supply-chain behavior, or unexpected mutation of Fetch API objects are in scope.