# Security Policy

## Supported versions

Security fixes are provided for the latest published release.

| Version | Supported |
| --- | --- |
| 0.1.x | Yes |
| Earlier | No |

## Reporting a vulnerability

Use [GitHub private vulnerability reporting](https://github.com/liznee/dsh-file-resource/security/advisories/new) when it is available. If the private form is unavailable, open a minimal Issue asking for a private contact channel without including exploit details, private document contents, credentials, local paths, or other sensitive data.

Include the affected version, impact, reproduction conditions, and a minimal proof of concept. Reports will be acknowledged as soon as practical. Please allow time for a fix and coordinated release before public disclosure.

## Scope

High-priority reports include cross-session data access, unintended network transmission, parser escapes, path traversal, archive decompression abuse, executable-file masquerading, and install-time code execution.
