# Security policy ## Reporting vulnerabilities Do not report suspected vulnerabilities, exploit inputs, or sensitive logs in public issues or pull requests. The planned reporting channel is GitHub Private Vulnerability Reporting on the official public repository. That repository and reporting channel are not available yet. Public release is blocked until maintainers configure and test the private reporting channel and replace this paragraph with its actual link. No response-time commitment is currently offered. Do not assume that a public issue is a private channel. ## Supported versions Version 0.1.0 is an unreleased candidate. There is no supported production release yet. Dependency scans and regression tests are release checks, not a guarantee that the validator is free of vulnerabilities. Validate suitability for your deployment before using its results for routing decisions.