# Security Policy ## Supported versions The newest npm `latest` release and any explicitly listed security-maintenance release receive security fixes. Release candidates on `next` are supported only until their corresponding stable release is published. ## Reporting a vulnerability Do not open a public issue for a suspected vulnerability or exposed credential. Use GitHub's private vulnerability report for this repository: https://github.com/guoxiucai/dsh-code/security/advisories/new Include the affected version, platform, reproduction steps, impact, and any suggested mitigation. Please allow the maintainer time to reproduce and coordinate a fix before public disclosure. Never include real API keys, npm tokens, session files, or crash logs that have not been reviewed and redacted.