Security fixes target the latest release published on npm. While the project is pre-1.0, older releases are not guaranteed to receive backports. Report suspected vulnerabilities privately by opening a draft repository security advisory from GitHub's Security tab. Do not open a public issue containing credentials, session cookies, API keys, exploit details, or customer data.
Include the affected revision, Odoo version and protocol, a minimal reproduction, and the security impact. Use synthetic secrets and disposable databases only.
The library treats passwords, API keys, database master passwords, and session
cookies as secrets. They must remain Redacted until the HTTP boundary and
must never appear in URLs, logs, error request snapshots, fixtures, or traces.