# Security policy ## Reporting a vulnerability Please report suspected vulnerabilities privately through GitHub's **Security** → **Report a vulnerability** flow for this repository. Do not open a public issue for an undisclosed vulnerability. Include the affected version, a minimal reproduction, impact, and any suggested mitigation. You can expect an acknowledgement within seven days. Supported versions and remediation timelines will be assessed case by case until the package reaches 1.0.