| Version | Supported |
|---|---|
| Latest 1.x release on npm | Yes |
| Older 1.x releases | No |
| 0.x | No |
Fixes are released as a new 1.x version on npm, so upgrade to the latest release to get them. See SUPPORT.md.
Releases are signed: to check one was built by this repository's release workflow, see Verifying a release.
Report it privately through GitHub: Report a vulnerability. Please don't open a public issue, pull request or discussion about it.
Include what you can of:
- the version and the import you use, e.g.
react-marketing-tools/server - the steps or a minimal example that reproduces it
- what an attacker could do with it
You'll get a first response within 14 days. The report stays private until a fix is released. The advisory is then published, crediting you unless you'd rather not be named.
Every fixed vulnerability is listed under Security in the changelog and in the notes of the GitHub Release that fixes it.
In scope: the code in this repository, which is the npm package and the playground. That includes personal data reaching an analytics platform despite redaction or denied consent.
Out of scope: vulnerabilities in Google Tag Manager, Google Analytics, the Meta Pixel or the Conversions API themselves. Report those to Google or Meta.