bread is pre-1.0 and all @breadai/* packages version in lockstep. Only the latest published
release receives security fixes — there are no maintained older lines yet.
Do not open a public issue. Report it privately via GitHub:
- Go to the Security tab of this repository.
- Click "Report a vulnerability" to open a private advisory.
This reaches the maintainer directly without exposing details (or an exploit path) to the public before a fix ships.
Include, where relevant: the affected package/version, a reproduction, and the impact you'd expect (e.g. RCE, credential leak, auth bypass, denial of service).
This is a solo-maintained project — there's no formal SLA, but reports are triaged as they come in and a fix or mitigation is prioritized over new feature work once confirmed.