Security fixes are released for the latest stable version of @postback/cli.
Upgrade to the current npm latest version before reporting an issue that may
already be fixed.
Do not open a public issue for a suspected vulnerability. Use the repository's private vulnerability reporting channel so maintainers can investigate before details are disclosed.
Include the affected CLI version, operating system and Node.js version, exact reproduction steps, impact, and any suggested mitigation. Never include live Postback tokens, provider credentials, raw device identifiers, or customer data.
Maintainers will acknowledge a complete report as soon as practical, keep the reporter updated while validating and fixing it, and coordinate disclosure after a patched release is available.