Angular DevTools is in early development. Only the latest published release of
@santoshyadavdev/ng-devtools is supported. There are no older release lines to backport a fix to.
Report a vulnerability privately through GitHub's private vulnerability reporting ("Report a vulnerability" on the repository's Security tab). Don't open a public issue for a security report.
Include what you'd include in any bug report: the version affected, how the devtools are set up (Angular CLI with Express, Vite, Analog, the standalone CLI, the MCP server or the Chrome extension), a description of the issue and, if you have one, a minimal reproduction.
This is a small project maintained in spare time, so there is no formal SLA. Expect an acknowledgement within a few days, and a fix or a public response once the report has been triaged. If the issue is confirmed, the fix goes out in the next release and the advisory credits you unless you ask otherwise.