# Security policy

## Supported versions

Only the latest release is supported.

## Reporting a vulnerability

Use GitHub private vulnerability reporting for a concrete vulnerability in the supported production path. Include the affected version or commit, expected and observed behaviour, and a small non-sensitive reproduction.

Do not include credentials, tokens, private content, screenshots, raw app-state payloads, elicitation contents or audit files. Do not open a public issue before the report has been assessed.
