# Security Policy ## Reporting a vulnerability Do not disclose exploitable vulnerabilities, proof-of-concept code, credentials, private URLs, or sensitive input files in a public issue or discussion. Use the repository's private vulnerability-reporting channel when it is available. If you cannot access a private reporting channel, do not disclose the vulnerability publicly. Repository maintainers must configure and verify a private reporting path before announcing the repository as public. Include the affected package version, runtime, a minimal reproduction, impact, and any known mitigation. Remove secrets and personal data from all material you provide. ## Supported versions Security fixes are evaluated for the latest published version. Reports affecting unsupported versions may require an upgrade before they can be investigated. ## Disclosure Please allow the maintainer time to assess and remediate a report before discussing it publicly. A public advisory or release note will be published when disclosure is appropriate.