# Security policy ## Supported versions Only the newest `preview` release is supported while the project is in public preview. ## Reporting a vulnerability Please use [GitHub private vulnerability reporting](https://github.com/ArmyWas/dsh-provider-passport/security/advisories/new). Do not open a public issue for credential exposure, request smuggling, SSRF, cross-origin access, settings corruption, or another security-sensitive finding. Include the plugin version, DSH version, operating system, impact, and a minimal reproduction that contains no real credentials or private endpoint. A local mock endpoint is preferred. The maintainer will acknowledge a valid report through the private advisory and coordinate a fix before public disclosure.