# Security Policy ## Supported Versions Security fixes are handled on the default branch before the first stable release. After stable releases begin, supported release lines will be documented here. ## Reporting A Vulnerability Please report suspected vulnerabilities privately by emailing security@essenciary.com. Include: - A description of the issue and the affected workflow. - Steps to reproduce or a proof of concept when possible. - The Githical version, operating system, and Git version involved. Do not open a public issue for a suspected vulnerability. The maintainers will acknowledge reports as soon as practical, investigate, and coordinate a fix or disclosure plan when the report is valid.