# Security policy ## Supported versions During public beta, only the most recent published beta release and the current `main` branch receive security fixes. ## Reporting a vulnerability Please do not report vulnerabilities in a public issue. Use GitHub's private vulnerability reporting from the repository's **Security** tab. Include reproduction steps, affected versions, likely impact, and any suggested mitigation. If private reporting is temporarily unavailable, open a public issue asking the maintainer to establish a private contact channel, but do not include vulnerability details. Reports will be acknowledged as soon as practical. A fix and disclosure plan will be coordinated privately before public details are released.