The main branch is considered the actively supported line.
Please do not open public issues for unpatched vulnerabilities.
Report security concerns via GitHub Security Advisories (preferred).
If Security Advisories are unavailable, open a GitHub issue with minimal details
and request private coordination.
Include:
- Affected component and version/commit
- Reproduction steps
- Impact assessment
- Suggested mitigation (if available)
Maintainers will acknowledge as soon as possible on GitHub.
- Acknowledge and triage report
- Reproduce issue and assess severity
- Prepare patch and regression tests
- Coordinate disclosure timeline
- Publish patch notes and mitigation guidance
- Treat all PPTX files as untrusted input.
- Configure
zipLimitsin production. - Run rendering in constrained browser/container contexts when possible.
- Keep dependencies and runtime updated.
- Disable or limit external navigation integration if your application does not need it.