OpenJSF's Security Collab Space has [recently published](https://github.com/openjs-foundation/security-collab-space/pull/247) their recommendations. Based on a quick skim, these are the related issues: - https://github.com/loopbackio/security/issues/32 - https://github.com/loopbackio/security/issues/19