Pastoralist is still iterating toward a stable v1 release. Security fixes are prioritized for the latest published release line.
| Version | Supported |
|---|---|
| Latest | ✅ |
Please do not open a public issue for suspected vulnerabilities.
Use GitHub's private vulnerability reporting if it is available for this repository:
https://github.com/yowainwright/pastoralist/security/advisories/new
If private reporting is not available, email the maintainer listed in
package.json.
Please include:
- Affected Pastoralist version or commit SHA
- Package manager and lockfile type involved, if relevant
- Minimal reproduction steps or a proof of concept
- Impact, including whether secrets, dependency updates, or generated PRs are involved
You should receive an acknowledgement within 7 days. Valid reports are triaged privately, fixed on the supported release line, and disclosed through a GitHub Security Advisory when appropriate.