# Security policy

## Supported versions

Security fixes are provided for the latest published version.

## Reporting a vulnerability

Please report vulnerabilities through GitHub's private security advisory feature for this
repository. Do not open a public issue containing exploit details, credentials, or other sensitive
information.

Include the affected package and version, reproduction details, expected impact, and any suggested
mitigation. A maintainer will acknowledge the report and coordinate disclosure through the private
advisory.
