Security fixes are released for the maintained @stackline/react-loading
version lines documented in the README. Use the latest patch release available
for the React line used by your application.
Report suspected vulnerabilities privately through GitHub Security Advisories. Do not publish exploit details in a GitHub issue.
Include the affected version, React and Node.js versions, a minimal synthetic reproduction, realistic impact, and any known mitigation. Remove credentials, personal data, and proprietary application code.
We aim to acknowledge reports within three business days, provide an initial assessment within seven business days, and send an update at least every fourteen days while confirmed remediation is active. Coordinated disclosure is preferred.