# Security policy ## Reporting a vulnerability Report privately to — do not open a public issue. Canonical repository: https://git.fromaitochitta.com/open/repo-standard Please include the affected version or commit, a minimal reproduction, and the impact you see. We acknowledge every report within 5 working days, agree a fix and disclosure timeline with the reporter, and aim to disclose within 90 days of the initial report. ## Response process 1. Acknowledge within 5 working days. 2. Triage and confirm severity within 10 working days. 3. Develop and test a fix. 4. Publish an advisory and credit the reporter unless they prefer to remain anonymous. ## Supported versions | Version | Supported | | ------- | --------- | | 0.11.x | :white_check_mark: | | < 0.11 | :x: | This project has not reached 1.0 yet; only the latest 0.x release line receives security fixes. See `CHANGELOG.md` for release history. ## Advisories No advisories have been published yet.