# Security policy ## Supported version Security fixes are provided for the latest released minor version. ## Reporting a vulnerability Please use GitHub private vulnerability reporting for this repository. If that interface is unavailable, open a public issue containing **no exploit details or private data** and ask the maintainer for a private contact channel. Do not attach real DSH sessions, credentials, proprietary code, or personal information. Build a minimal synthetic reproduction. Reports should include affected version, impact, reproduction conditions, and a suggested mitigation when known. You can expect an acknowledgement within seven days.