# Security Policy ## Supported Versions Security updates are provided for the following versions: | Version | Supported | | ------- | ------------------ | | 5.x | :white_check_mark: | Older versions are not supported. Please upgrade to the latest release. ## Reporting a Vulnerability We use GitHub Security Advisories for reporting vulnerabilities. **Please do NOT open a public GitHub issue for security vulnerabilities.** To report a vulnerability: 1. Go to the [Security Advisories](https://github.com/FrankNFT-labs/ERC721F/security/advisories) page 2. Click "Report a vulnerability" 3. Fill out the vulnerability report template ## Response Timeline We aim to respond to security reports within **48 hours**. - **High priority** (critical impact): Acknowledge within 48h, target fix within 1-2 weeks - **Medium priority**: Acknowledge within 48h, target fix in 2-4 weeks - **Low priority** (minor impact, theoretical): Acknowledge within 48h, fix in next release We appreciate responsible disclosure and will work with reporters to understand and address issues. ## Scope This policy covers the contracts in the `contracts/` directory. The following are out of scope: - Example contracts in `examples/` - User-provided deployment configurations - Third-party integrations ## Disclosure Policy - Public disclosure will be coordinated after a fix is available - We request that reporters give us reasonable time to address the issue before public disclosure