Please report vulnerabilities privately via GitHub's private vulnerability reporting ("Report a vulnerability" under the repo's Security tab).
Do not open a public issue for a security problem.
We aim to acknowledge reports within a few business days. Please include a
reproduction and the version of ax affected (ax --version).
Only the latest published version on npm receives security fixes.