If you believe you've found a security vulnerability in @stedi/sdk or stedi, don't open a public issue. Email security@stedi.com with:
- A description of the vulnerability.
- Steps to reproduce.
- Affected versions.
- Any proof-of-concept you have.
We'll acknowledge within two business days and follow up with an estimated remediation timeline. Coordinated disclosure terms negotiable case-by-case.
Security fixes ship in the next release from main. Only the latest published version of @stedi/sdk and stedi is supported — upgrading to the newest release is how you receive a fix. We do not maintain release branches or backport fixes to earlier versions.
When a new major version ships, the previous major is no longer supported from that date.