# Security Policy ## Supported Versions Security fixes are provided for the latest published release. Reports against the current `main` branch are also welcome when they describe an issue that is not present in the latest release. | Version | Supported | |---|---| | Latest published release | Yes | | Older releases | No | ## Report a Vulnerability Privately Do not open a public GitHub Issue for a suspected vulnerability. Use [GitHub private vulnerability reporting](https://github.com/TX230/winproc-tui/security/advisories/new) so the report and follow-up discussion remain private. Include: - the affected version or commit; - the security impact and affected data or boundary; - minimal reproduction steps or a proof of concept; - any known mitigation or workaround. `winproc-tui` can display process paths, open files, command lines, and environment variables. Remove passwords, tokens, personal paths, and other secrets from screenshots, recordings, and diagnostic material before attaching them. The maintainer will review reports on a best-effort basis and coordinate disclosure after a fix or mitigation is available. Do not publish vulnerability details before that coordination is complete.