# KitJS security policy

## Report a vulnerability privately

Do not disclose a suspected vulnerability in a public issue, discussion, pull
request, or social post.

Use the repository's private vulnerability-reporting form:

https://github.com/kitwork/kit.js/security/advisories/new

Include the affected KitJS version and profile, the smallest safe reproduction,
the expected and observed behavior, and your impact assessment. Do not include
secrets or data belonging to other people.

The public issue tracker is appropriate only for non-sensitive defects.

## Scope and support

The stable support target represented by this checkout is `1.0.0`. Its public
support evidence consists of the exact tag, package, CDN artifacts, and npm
channel recorded in `SUPPORT.md` and `RELEASE_READINESS.md`. The
`1.0.0-rc.2` and older RC/`0.9` artifacts are historical and are not patched
in place. Public
release availability is recorded at https://github.com/kitwork/kit.js/releases.
This policy provides a private reporting path; it does not expand the runtime's
compatibility or support guarantees.
