# Security policy ## Supported version Security fixes are applied to the current `main` branch and the production deployment at . ## Reporting a vulnerability Do not open a public issue for an unpatched vulnerability. Use GitHub's **Report a vulnerability** private reporting flow in the repository Security tab and include: - affected URL, file or commit; - reproduction steps and impact; - browser and operating system; - screenshots or a minimal proof of concept when helpful. Please do not access other users' data, degrade the production service or publish an exploit before a fix is available. The maintainer will acknowledge a valid report when practical and coordinate disclosure after remediation. For rendering bugs, layout regressions and non-security failures, use the normal bug report template.