Draupnir is currently pre-1.0 and released as a single rolling 0.x line.
Only the latest published version on npm receives security fixes.
| Version | Supported |
|---|---|
Latest (0.4.x) |
✅ |
| < 0.4 | ❌ |
If you discover a security vulnerability, please do not open a public GitHub issue. Instead, report it privately:
- Email: [email protected]
- Or use GitHub's private vulnerability reporting
Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce, or a minimal proof-of-concept
- Any suggested remediation, if you have one
You should receive an acknowledgment within a few days. Once the issue is confirmed, a fix will be prepared and a new version published to npm; the reporter will be credited unless anonymity is requested.