# Security Policy ## Supported versions Security fixes are applied to the latest published version. ## Reporting a vulnerability Please do not open a public issue for a vulnerability involving credential exposure, arbitrary file access, or code execution. Use GitHub's private vulnerability reporting for this repository instead. Do not include passwords, tokens, raw Codex session files, or other personal data in a report. A minimal synthetic reproduction is preferred. For ordinary bugs that do not have a security impact, open a regular GitHub issue.