Security fixes go to the newest stable release, not to older releases or previews. Until the first stable release, they go to the latest preview release. The npm registry metadata lists the published versions
Report vulnerabilities privately through GitHub's private vulnerability reporting. Open the repository's Security tab and select "Report a vulnerability"
Do not open public issues, pull requests or discussions for vulnerabilities. Include the affected version, the impact and the steps to reproduce, without real tokens or other credentials
Reports are reviewed as maintainer time allows, with no guaranteed response time