# Security Policy
## Supported versions
| 0.1.x | Yes |
## Reporting a vulnerability
Please **do not** open a public GitHub issue for security vulnerabilities.
Instead, report privately via one of:
- GitHub Security Advisories: <https://github.com/thanos/apo/security/advisories/new>
- Email the maintainer listed on the GitHub profile for [thanos/apo](https://github.com/thanos/apo)
Include:
1. Description of the issue
2. Steps to reproduce
3. Affected versions / commit SHA
4. Impact assessment if known
We aim to acknowledge reports within 7 days and ship a fix or mitigation as soon as practical.