# Security Policy

## Supported Versions

Security updates are provided for the latest published version.

## Reporting a Vulnerability

Please report security issues privately through GitHub security advisories when available, or contact the maintainer through the repository. Do not disclose vulnerabilities publicly until reviewed.

## Privacy

pi-vuln-scanner is designed to avoid sending local source code to external services. Network scanners should send package coordinates only, such as npm package name and version.
