# Security Policy

## Supported versions

Only the latest published Angular 22 release of the `@ojiepermana/*` package suite receives
security fixes. Older releases should be upgraded before a report is investigated.

## Reporting a vulnerability

Do not open a public issue for a suspected vulnerability. Email `me@ojiepermana.com` with:

- the affected package and version;
- a minimal reproduction or proof of concept;
- the expected impact; and
- any suggested mitigation, if known.

Do not include production credentials, personal data, or third-party secrets. Reports are
acknowledged and handled privately before a coordinated fix is published.
