# Security Policy

## Supported versions

Only the latest released version of SLASHED receives security fixes. Update
before reporting.

## Reporting a vulnerability

Report privately — **do not open a public issue or PR.** Use
[GitHub Security Advisories](https://github.com/codeslash-dev/SLASHED/security/advisories/new).

Please include:

- affected version (the `/*! SLASHED vX.Y.Z */` bundle header or release tag);
- which artifact is affected (CSS bundle, `configurator/` app, or build tooling);
- steps to reproduce or a proof of concept;
- impact.

Vulnerabilities in the WordPress integration belong in the
[SLASHED-Plugins repo](https://github.com/codeslash-dev/SLASHED-Plugins/security/advisories/new).

We aim to acknowledge a report within a few days, share a fix timeline once
triaged, and credit reporters in the release notes unless you prefer otherwise.
