The project ships from master as @jshookmcp/jshook on npm. Security
updates are backported to the current minor release line; older lines are
supported only as community maintenance.
| Version | Supported |
|---|---|
| 0.3.x | ✅ |
| 0.2.x | ✅ |
| < 0.2 | ❌ |
Please report security issues privately instead of opening a public issue:
- Open a GitHub Security Advisory at https://github.com/vmoranv/jshookmcp/security/advisories/new, or
- Email the maintainer via the address listed in the repository profile, or
- Open a private issue via the GitHub security reporting flow.
You can expect an acknowledgment within 7 days and a fix/assessment within 30 days, depending on severity. If the report is accepted, a patched release will be published and the advisory disclosed after users have had a chance to upgrade. If it is declined, the reasoning will be explained to the reporter.
Please do not include real credentials, traffic captures, or production secrets in the report.