# Security - **Supported runtime:** TouchSpin is developed and released on Node.js 22 with Yarn 4 (Berry). Earlier Node versions may work but are best-effort. - **How to report:** Use [GitHub Security Advisories](../../security/advisories/new) from this repository’s *Security* tab to open a private report. Provide reproduction steps, affected package names, and any mitigation ideas. - **Response expectations:** This project is maintained on a best-effort basis—there are no guaranteed timelines. You will receive replies through the advisory thread when the maintainer is available. - **Release provenance:** Official npm publishes run from GitHub Actions with `npm publish --provenance` so consumers can verify artifacts via npm’s attestation view. Please avoid posting potential vulnerabilities in public issues or discussions until we have had a chance to review them privately.