# Security policy ## Supported versions Security fixes are made on the latest released version of dsh-forge. Upgrade to the newest release before reporting an issue that may already be fixed. ## Reporting a vulnerability Do not open a public issue for a suspected vulnerability. Use [GitHub private vulnerability reporting](https://github.com/maxmilian/dsh-forge/security/advisories/new) instead. Include the affected version, Gitea or Forgejo version, impact, reproduction steps, and any suggested mitigation. Remove tokens, credentials, private repository contents, and private instance URLs from the report. The maintainer will assess the report, coordinate a fix and disclosure when appropriate, and credit reporters who wish to be acknowledged.