# Security Policy

## Supported versions

Security fixes are applied to the latest published version.

## Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Use GitHub's private vulnerability reporting feature for this repository, or contact the maintainer privately through the contact method listed on the repository profile. Include a clear description, reproduction steps, affected versions, and potential impact. Do not include credentials, endpoint headers, or other secrets.

You should receive an acknowledgement within seven days. Valid reports will be investigated and a fix will be released as soon as reasonably possible.
