Only the latest major version receives security updates.
| Version | Supported |
|---|---|
| 1.x | ✅ |
| < 1.0 | ❌ |
Please do not open a public GitHub issue for security vulnerabilities.
Use GitHub Private Vulnerability Reporting to report issues privately. You can expect a response within 7 days.
Include in your report:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
This package is a collection of SVG icons and operator metadata. It contains no authentication, user data, or server-side logic. Likely relevant vulnerabilities include:
- Malicious SVG content (XSS via inline scripts or external references)
- Dependency vulnerabilities (flagged automatically via Dependabot)
- Issues in third-party dependencies (report directly to those maintainers)
- Vulnerabilities in applications that consume this package