# Security policy ## Supported versions Before the first release, security fixes target the current default branch. After the first `0.1.x` release, fixes target the latest `0.1.x` version; older versions may not receive fixes. ## Reporting a vulnerability Please do not open a public issue for a suspected bypass, header-parsing flaw, authentication issue, exposure of DSH, or credential leak. After the repository is published, use GitHub's private security advisory flow for this repository. Include a minimal reproduction, affected version or commit, impact, and any mitigations you have identified. Allow time for triage and a coordinated fix before public disclosure. Particularly useful reports cover direct-access bypasses, spoofed or duplicate identity headers, Host/Origin validation, HTTP/WebSocket proxying, and behavior around Tailscale Serve versus Funnel. Reports about the opt-in Serve manager should include the observed `serve status --json` shape and whether it could overwrite, misclassify, or falsely report a route.