# Security Policy
## Supported versions
Cindermark is pre-1.0. Security fixes are released against the latest `0.x`
version — please always depend on the most recent release.
| latest 0.x | ✅ |
| older | ❌ |
## Reporting a vulnerability
**Please do not open a public issue for security vulnerabilities.**
Report privately through GitHub's
[Report a vulnerability](https://github.com/renedeanda/cindermark/security/advisories/new)
form (repo → **Security** → **Advisories**). If private reporting isn't
available, open a minimal issue asking for a private contact channel — without
disclosing any details.
You can expect an initial response within a few days. Once a fix is ready we'll
coordinate a release and credit you, unless you'd prefer to stay anonymous.