# Security Policy ## Supported versions OpenOPC does not yet publish versioned releases. Security fixes are made on the latest `main` branch; older commits are not supported. ## Reporting a vulnerability Please do not disclose suspected vulnerabilities in a public issue or discussion. Use GitHub's [private vulnerability reporting](https://github.com/HKUDS/OpenOPC/security/advisories/new) to send the maintainers: - the affected commit and environment; - impact and required preconditions; - a minimal, non-destructive reproduction; and - any suggested mitigation or regression test. Use synthetic credentials and loopback endpoints whenever possible. The maintainers will coordinate validation, remediation, and disclosure with the reporter through the private advisory.