# Security Policy

## Supported Versions

Gessi is early-stage. Security fixes target the latest published version.

## Reporting a Vulnerability

If you find a security issue, please do not open a public issue with exploit
details.

Instead, contact the maintainer privately through GitHub or npm. Include:

- A short description of the issue.
- Steps to reproduce it.
- Any affected versions or CDN URLs.
- Suggested fixes, if you have them.

The maintainer will review the report and respond as soon as possible.

