Do not report security vulnerabilities in a public issue, discussion, or pull request.
Use Report a vulnerability in the Security tab of the affected repository. If private vulnerability reporting is unavailable, email support@antelopejs.com with the repository, affected version, impact, reproduction steps, and any suggested mitigation.
We will acknowledge the report, investigate it, and coordinate disclosure with the reporter. Please allow maintainers reasonable time to release a fix before publishing details.
Security fixes target supported releases. Unless a repository documents a different policy, use its latest stable version before reporting a problem.