# Security policy ## Supported versions Only the latest tagged Theme Lab release is supported with security fixes. Compatibility is currently limited to the DeepSeek Harness preview version documented in the README. ## Reporting a vulnerability Do not open a public issue for a suspected vulnerability. Use **GitHub → Security → Report a vulnerability** to submit a private advisory to the repository owner. Include affected versions, reproduction steps, impact, and any proposed mitigation. Remove tokens, paths, personal data, and other secrets from screenshots or logs. You should receive an acknowledgement within seven days. Please allow time for triage and a coordinated fix before public disclosure. This project cannot promise rewards or a fixed remediation timeline. For vulnerabilities in DeepSeek Harness itself, follow the upstream project’s security policy rather than reporting them here.