# Security Policy

## Reporting A Vulnerability

Please do not open a public issue for sensitive security reports.

Send a private report to the repository owner through GitHub's private vulnerability reporting when
available, or contact the maintainer directly.

Include:

- affected package and version;
- reproduction steps;
- impact;
- suggested fix, if known.

## Supported Versions

Security fixes target the latest released version.
