Security fixes are applied to the latest release on the most recent major version line.
| Version | Supported |
|---|---|
| 2.x | ✅ |
| < 2.0 | ❌ |
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, report them privately through
GitHub's private vulnerability reporting
(Security → Report a vulnerability on this repository). If that is not
available to you, contact the maintainers listed in
package.json directly.
Please include, where possible:
- the affected version(s),
- a description of the issue and its impact,
- steps to reproduce or a minimal proof of concept.
- We will acknowledge your report, usually within a week.
- We will investigate and keep you informed of our progress.
- Once a fix is available, we will coordinate the disclosure and release with you, and credit you for the discovery unless you prefer to remain anonymous.
Thank you for helping keep N3.js and its users safe.