# Security Policy

## Supported versions

Security fixes are applied to the latest published version of `@nguyenquangthai/pi-ask`.

## Reporting a vulnerability

Please do **not** open a public issue for a suspected vulnerability. Report it privately to [@QuangThai](https://github.com/QuangThai) with:

- a concise description and impact;
- steps to reproduce or a proof of concept;
- affected version(s); and
- any suggested mitigation.

You will receive an acknowledgement within 7 days. If confirmed, a fix and coordinated disclosure will follow as soon as practical.
