# Security Policy
## Supported Versions
| 0.1.x | Yes |
## Reporting a Vulnerability
If you discover a security vulnerability in bzr, please report it responsibly:
1. **Do not** open a public GitHub issue
2. Email [randomparity@gmail.com](mailto:randomparity@gmail.com) with:
- Description of the vulnerability
- Steps to reproduce
- Affected version(s)
3. You will receive a response within 72 hours acknowledging your report
4. A fix will be developed privately and released as a patch version
## Scope
Security issues in bzr itself and its direct dependencies are in scope.
Issues in upstream Bugzilla servers are out of scope — report those to
the Bugzilla project directly.