# Security policy

## Reporting a vulnerability

Please do **not** disclose vulnerability details in a public issue.

Use GitHub's private vulnerability reporting for `ArtOfIntel/pi-rich-questions`: open the repository's **Security** tab, choose **Advisories**, and select **Report a vulnerability**. Include the affected version, impact, reproduction steps, and any suggested mitigation. Redact credentials and unrelated private data.

If **Report a vulnerability** is unavailable, open a minimal public issue titled **Security contact request**. Include no technical details, logs, exploit steps, credentials, or other sensitive information; ask the maintainer to establish a private reporting channel. This project does not publish a security email address.

## Scope and versions

Reports about extension execution, provider data flow, configuration handling, result disclosure, or package supply-chain behavior are welcome. Pi core or provider vulnerabilities should also be reported to their respective maintainers.

There is no fixed support window or guaranteed response timeline. Reproduce against the latest released version when possible and state every affected version you verified. Security-relevant fixes will be documented in the changelog when disclosure is appropriate.

For safe-use guidance, see [Security and privacy](docs/security-and-privacy.md).
