# Security Policy ## Supported versions Security fixes are released for the latest npm version of `@anionex/dsh-smarter-edit`. Older releases are handled on a best-effort basis. ## Reporting a vulnerability Do not open a public issue for security problems. Use GitHub's private vulnerability reporting for this repository and include: - affected package, DSH, Node.js, profile, provider, and operating-system versions; - the smallest patch input and file layout that reproduce the issue; - the impact you observed, especially any sandbox or path-boundary bypass; - logs with credentials, tokens, private paths, and sensitive source removed. We aim to acknowledge reports within five business days and will continue the private thread until a fix, workaround, or documented resolution is available. For non-security questions, see [SUPPORT.md](SUPPORT.md).