# Security Policy
## Supported Versions
| latest | Yes |
| < latest | No |
Only the most recent published version receives security fixes.
## Reporting a Vulnerability
**Do not open a public GitHub issue for security vulnerabilities.**
Please report vulnerabilities through
[GitHub Security Advisories](https://github.com/o3co/rs.hocon/security/advisories/new).
### What to include
- Description of the vulnerability
- Steps to reproduce (minimal HOCON input, code snippet, etc.)
- Impact assessment (denial of service, information disclosure, etc.)
- Suggested fix, if you have one
### Response timeline
- **Acknowledgment**: within 7 days of report
- **Assessment and fix**: best effort, depending on severity
We will coordinate disclosure with you before publishing any advisory.