# Security Policy ## Supported versions Security fixes are applied to the latest commit on the `main` branch. This repository does not currently publish versioned releases, so older commits and forks are not maintained as separate security-support channels. ## Report a vulnerability privately Please use [GitHub private vulnerability reporting](https://github.com/cathrynlavery/diagram-design/security/advisories/new). Do not disclose a suspected vulnerability in a public issue, pull request, discussion, or social-media post before we have coordinated disclosure. Include as much of the following as you can: - the affected file, script, or workflow; - a description of the impact and who could be affected; - clear reproduction steps or a minimal proof of concept; - any conditions required to exploit the issue; - a suggested mitigation, if you have one. Avoid including secrets, credentials, or personal data in the report. ## What to expect We will acknowledge the report as soon as practical, validate the finding, determine its scope, and coordinate remediation and disclosure with the reporter. Please allow time for a fix to be developed and tested before public disclosure. ## Good-faith research Please avoid accessing, modifying, or deleting data that does not belong to you, disrupting services, or degrading other users' experience. If testing could affect other people or systems, stop and submit a private report first. Thank you for helping keep Diagram Design and its users safe.