usesteady@0.1.0-alpha.72 is an affected historical release. On Windows, an approved filesystem mutation can traverse a junction/reparse point from an apparent in-workspace path to a location outside the workspace.
usesteady@0.1.0-alpha.73 corrected the tested Windows junction/reparse path. The npm alpha dist-tag currently resolves to 0.1.0-alpha.73. A separate, confirmed hardlink alias-object defect affects existing-file mutations in that released package. The .73 junction result remains valid, but .73 is not a correction for the hardlink finding. No publicly verified successor for that separate finding is claimed here.
No upgrade command to the current alpha dist-tag is recommended as a correction for the separate hardlink finding. Assess the named risks before using .73.
For 0.1.0-alpha.72:
.72 as affected even though the interactive approval gate still applies.The issue in .72 does not bypass the interactive approval gate. It affects where an approved filesystem operation may ultimately land.
For .73, avoid existing-file mutation commands on untrusted workspaces containing hardlinks. Approval still applies, but does not repair the receiver-identity defect. Do not treat the current alpha dist-tag as a correction for this separate finding.
The .73 successor was released after Windows junction/reparse containment regression, cross-platform effect-decision checks, exact-package verification, and clean Linux/Windows installation proof. This remains a claim about that tested junction issue and release evidence. The later hardlink finding is distinct. Neither result is a universal filesystem-security or Production-readiness guarantee.
0.1.0-alpha.72 remains documented as junction-affected; publishing .73 did not retroactively change .72. 0.1.0-alpha.73 remains documented as hardlink-affected until a separately verified successor is public.
Also published on GitHub SECURITY.md.
Report new vulnerabilities privately to support@usesteady.dev.