# Security Policy Thanks for helping keep `dsh-gsd-bundle` and its users safe. This document explains how to report a security vulnerability and which versions receive security fixes. ## Reporting a Vulnerability Please report security vulnerabilities **privately** using GitHub's built-in private vulnerability reporting feature: 1. Open the repository's **Security tab** at . 2. Click **Report a vulnerability**. 3. Fill in the advisory form with as much detail as you can: a description of the issue, the affected version(s), steps to reproduce, and any impact you have identified. Please do **not** open a public issue or pull request for a security vulnerability, and do not share details in public channels before a fix is released. Reporting privately lets us coordinate a fix and disclosure without exposing the issue to others. We will acknowledge your report and work with you to understand and address it. We ask that you give us a reasonable window to investigate and release a fix before disclosing the vulnerability publicly. ## Supported Versions This is a small plugin bundle with a single maintained line. Only the **most recent published release** receives security fixes. If you are using an older release, please upgrade to the latest version to receive security updates. | Version | Supported | | ------- | --------- | | Latest published release | ✅ | | Older releases | ❌ |