This repository follows the security policy of the Verdaccio project, which lists the supported versions and explains how to report a vulnerability privately:
SECURITY.md in verdaccio/verdaccio
Please do not open a public issue to report a vulnerability.