# Security Policy ## Supported Versions At any given time we support the _latest_ version of inkstand (as reflected in the _main_ branch) with security updates. ## Reporting a Vulnerability If you think you have found a vulnerability, please report it responsibly. Do not create a GitHub issue for a security problem. Instead, open a private report through [GitHub's advisory form](https://github.com/jboix/inkstand/security/advisories/new). We appreciate any responsible disclosure of vulnerabilities that might impact the integrity of our users and their projects. We do not offer bounties, but if you wish we will credit you in the release notes. Before reporting, make sure you are on the latest version of inkstand and a supported Node version (22 or later).