- [Security Policy](#security-policy)
  - [Supported Versions](#supported-versions)
  - [Reporting a Vulnerability](#reporting-a-vulnerability)


# Security Policy

## Supported Versions

We release patches for security vulnerabilities. Which versions are eligible
receiving such patches depend on the CVSS v3.0 Rating:

| CVSS v3.0 | Supported Versions                        |
| --------- | ----------------------------------------- |
| 9.0-10.0  | Releases within the previous three months |
| 4.0-8.9   | Most recent release                       |

## Reporting a Vulnerability

Information regaring Zebra's Software security disclosure policy can be found on Zebra's website on the [ZEBRA VULNERABILITY DISCLOSURE](https://www.zebra.com/us/en/support-downloads/lifeguard-security/vulnerability-disclosure.html) page.
 

**Reporting Security Issues** 
Zebra embraces vulnerability reports from security researchers, customers, third-party component vendors, and other external groups that 
want to report a vulnerability in a Zebra Product/Solution ([VDP reporting page](https://hackerone.com/zebra_vdp).
