# Security policy

## Supported versions

Security fixes are released for the latest published major version. Upgrade to
the latest release before reporting an issue that may already be fixed.

## Reporting a vulnerability

Do not open a public issue for a suspected vulnerability.

Email hi@cavuno.com with:

- the affected package and version;
- a clear description of the impact;
- reproduction steps or a minimal proof of concept; and
- any suggested remediation or disclosure deadline.

Do not include live API keys, access tokens, customer data, or other secrets.
Use synthetic data and revoke any credential accidentally exposed during
testing.

We will acknowledge a report as soon as practical, keep you informed while it
is investigated, and coordinate disclosure after a fix is available. Please
allow reasonable time for remediation before publishing details.

Testing must stay within accounts and boards you own or are authorized to use.
Do not disrupt service, access other users' data, or use social engineering.
