# Security Policy
## Supported Versions
Only the latest release is supported with security updates.
## Reporting a Vulnerability
If there are any vulnerabilities in **Cairo extension for Visual Studio Code**, don't hesitate to
_report them_.
1. If you found a vulnerability in **Cairo language/compiler**, please consult its
own [security policy](https://github.com/starkware-libs/cairo/security/policy).
2. If you found a vulnerability in **Cairo extension for Visual Studio Code**, please consult its
own [security policy](https://github.com/software-mansion/vscode-cairo/blob/main/SECURITY.md).
3. Use the GitHub Security site for reporting vulnerabilities. You can report
one [here](https://github.com/software-mansion/cairols/security/advisories/new).
4. Please **do not disclose the vulnerability publicly** until a fix is released!
5. Once we have either a) published a fix or b) declined to address the vulnerability for whatever
reason, you are free to publicly disclose it.