# Security policy

**English** · [简体中文](./SECURITY.zh-CN.md)

## Supported versions

The latest released minor version receives security updates. Pre-releases are for verification only and carry no long-term maintenance commitment.

## Reporting a vulnerability

Please report privately via **Security → Report a vulnerability** on the GitHub repository. Do not open a public issue.

Include the affected versions, a minimal reproduction, the scope of impact and, if you have one, a suggested fix. A maintainer will confirm as soon as possible and coordinate disclosure timing until a fix is available. Please do not access systems or data that are not yours while testing.

This project will never ask a reporter for passwords, tokens, private keys or other sensitive credentials.
