# Security policy

## Supported versions

| Version | Supported |
| ------- | --------- |
| 1.8.x   | Yes       |
| Older   | No        |

## Reporting a vulnerability

Please use GitHub's private vulnerability reporting for this repository rather than opening a public issue:

https://github.com/montasim/http-status-lite/security/advisories/new

Include reproduction steps, expected impact, affected versions, and a suggested fix when available. You should receive an acknowledgement within 48 hours.

## Security posture

The published package has no runtime dependencies and performs no network, file-system, or process operations. Registry synchronization and package verification scripts are development-only and are not executed when applications import the package.
