# Security Policy

## Supported Package

Security fixes are provided for the latest published version of
`@call-e/codex-plugin`.

## Reporting A Vulnerability

Please report security issues privately to `security@call-e.ai`.

When possible, include:

- a description of the issue
- affected package version
- reproduction steps
- impact assessment

We will acknowledge reports as quickly as practical and work with reporters on
coordinated disclosure.

Please do not open public GitHub issues for undisclosed vulnerabilities.
