Nothing changed! You can continue using @supabase/auth-js as normal. Nothing has changed in the way the package is published!
There's a remote code execution vulnerability in Notepad which is leveraged via the recently introduced formatting abilities to make tables in the app.