A patch release closes a sandbox escape in a dependency. No configuration changes required.
✦ Recommended next action
Apply the patch. It is a drop-in update for production installations.
Latest meaningful change
v1.4.3Security2026-07-23✓No migration required
Patches a sandbox escape in a browser dependency. No configuration or API changes.
Authority Score breakdown
96/ 100− no change this weekHigh confidence
Repository provenance100
Vendor-published.
Maintainer activity97
Daily commits.
Release consistency96
Regular patch cadence.
Security history88
One advisory this month, patched in 2 days.
Dependency health94
Current.
Documentation quality95
Thorough.
Issue responsiveness93
Median first response 10 hours.
Adoption signals98
Very widely used.
Independent tutorial coverage92
Good coverage.
Community sentiment95
Positive.
License clarity100
Apache 2.0.
Ownership stability100
Stable.
Safety Security failures and malicious behaviour are never averaged away by popularity. A low security or ownership dimension caps the overall score regardless of adoption.