# Security Policy

Thanks for helping keep `dsh-gsd-bundle` and its users safe. This document
explains how to report a security vulnerability and which versions receive
security fixes.

## Reporting a Vulnerability

Please report security vulnerabilities **privately** using GitHub's built-in
private vulnerability reporting feature:

1. Open the repository's **Security tab** at
   <https://github.com/jaaty/dsh-gsd-bundle/security>.
2. Click **Report a vulnerability**.
3. Fill in the advisory form with as much detail as you can: a description of
   the issue, the affected version(s), steps to reproduce, and any impact you
   have identified.

Please do **not** open a public issue or pull request for a security
vulnerability, and do not share details in public channels before a fix is
released. Reporting privately lets us coordinate a fix and disclosure without
exposing the issue to others.

We will acknowledge your report and work with you to understand and address it.
We ask that you give us a reasonable window to investigate and release a fix
before disclosing the vulnerability publicly.

## Supported Versions

This is a small plugin bundle with a single maintained line. Only the **most
recent published release** receives security fixes. If you are using an older
release, please upgrade to the latest version to receive security updates.

| Version | Supported |
| ------- | --------- |
| Latest published release | ✅ |
| Older releases | ❌ |
