# Security Policy
## Supported Versions
| latest | yes |
| < 1.0 | no |
## Reporting a Vulnerability
**Please do not open a public GitHub issue for security vulnerabilities.**
Report them privately using one of these channels (in order of preference):
1. **GitHub private vulnerability reporting** — click "Report a vulnerability" on the
[Security tab](https://github.com/mikelane/git-prism/security/advisories/new)
2. **Email** — contact the maintainer directly (check the repository profile)
### What to include
- Description of the vulnerability and potential impact
- Steps to reproduce
- Affected versions
- Any suggested fix (optional)
### Response timeline
| Acknowledgement | 48 hours |
| Initial assessment | 5 business days |
| Fix or mitigation | Depends on severity |
| Public disclosure | After fix released |
We follow responsible disclosure — we will coordinate a public advisory with you
once a fix is available.