# Security policy ## Supported versions Security fixes are applied on the default branch (`main`) when practical. Use the latest commit for deployments. ## Reporting a vulnerability Please **do not** open a public GitHub issue for undisclosed security problems. Use **GitHub private vulnerability reporting** for this repository: [Submit a private security advisory](https://github.com/hansjone/netx/security/advisories/new) Include: - A short description of the impact - Steps to reproduce (or proof-of-concept) if you can share them safely - Affected API route, UI surface, or dependency (if known) We will treat reports as confidential and coordinate a fix and disclosure timeline with you when possible.