Do not report security vulnerabilities in a public issue.
Use GitHub's private vulnerability-reporting form:
https://github.com/clickalong/sdk/security/advisories/new
Include the affected version, a minimal reproduction, the expected impact, and any suggested remediation. We will acknowledge a complete report, investigate it privately, and coordinate disclosure after a fix is available.
For vulnerabilities in the hosted Clickalong service rather than this SDK, contact Clickalong through https://clickalong.ai.
Security fixes are applied to the latest published version of
@clickalong/sdk.