# Security Policy ## Supported versions `dsh-narra-channel` and DeepSeek Harness are currently developer previews. Security fixes are provided for the latest published plugin version only. | Version | Supported | | --- | --- | | 0.1.5 | Yes | | < 0.1.5 | No | ## Reporting a vulnerability Do not open a public issue for a suspected vulnerability, leaked credential, or exploitable binding URL. Use GitHub private vulnerability reporting from the repository's **Security** tab, or open a private security advisory at: https://github.com/NetMind-AI/dsh-narra-channel/security/advisories/new Include the affected plugin and Harness versions, impact, reproduction steps, and any suggested mitigation. Remove live Narra binding URLs, Gateway tokens, API keys, personal message content, and other credentials from screenshots and logs. We will acknowledge a complete report as soon as practical, investigate it privately, and coordinate disclosure after a fix or mitigation is available.