# Security Policy ## Supported versions The `0.1.x` line receives security fixes. Development snapshots and superseded release candidates are not supported after a replacement candidate is issued. ## Reporting a vulnerability Do not disclose suspected vulnerabilities in a public issue. Before the public GitHub repository is created, report them privately to the distribution maintainer. After publication, use the repository's private security-advisory reporting channel. Include the affected version, platform, Harness version, reproduction steps, and the least sensitive evidence needed to validate the issue. Remove tokens, credentials, repository contents, and personal data. ## Security boundary This package provides evidence-backed assessment and release-gate inputs; it does not guarantee that software is vulnerability-free. Supported ecosystems, platforms, analyzers, providers, limitations, and evidence scope remain part of each assessment and release claim.