Kin Store publishes core, plugins, and react as independent packages, each
versioned on its own. Security fixes target the latest published version of each
package; older versions are not patched.
Please do not open a public GitHub issue for security vulnerabilities.
Instead, use GitHub's private reporting feature: go to the Security tab and click "Report a vulnerability". This opens a private advisory visible only to the maintainer until a fix is ready, and lets us coordinate a disclosure timeline with you.
We'll acknowledge new reports as soon as we can and follow up with next steps once the issue has been assessed.