Security fixes are made for the latest version of DeployProof published under
the npm latest tag. Please upgrade to the latest release before reporting a
problem that may already be fixed.
Please report suspected vulnerabilities through GitHub private vulnerability reporting. Do not disclose security-sensitive details in a public issue.
Include the affected version, impact, reproduction steps, and any suggested mitigation. Reports should not include live credentials, authorization headers, cookies, or private response data. We aim to acknowledge reports within seven days and will coordinate disclosure after a fix is available.