The current major version of the library receives security updates. New builds are produced via Github actions immediately after a security PR is reviewed & merged. NPM releases are published through trusted publishing via Github Actions only.
Go to https://github.com/Flux159/mcp-server-kubernetes/security/advisories and click "Report a vulnerability" and fill out the report. Please be descriptive as reports will be used to request a CVE disclosure from Github.