Please report suspected vulnerabilities privately through GitHub's security advisory feature. Do not include secrets, private repository content, or exploit details in a public issue.
The v2 alpha supports maintained Node.js releases declared in package.json. Security fixes target the latest alpha and the latest stable release, when one exists.