# Security Policy ## Supported Versions Security fixes are provided for the latest published Nutify release. ## Reporting A Vulnerability Do not disclose a suspected vulnerability in a public issue. Use GitHub's private vulnerability reporting for this repository. Include the affected version, deployment mode, reproduction steps, impact, and relevant sanitized logs. Never include passwords, API tokens, OIDC secrets, SMTP credentials, private keys, session cookies, or a production `SECRET_KEY`. The report will be acknowledged as soon as practical. Confirmed issues are fixed privately before coordinated disclosure and release.