# Security Policy
## Supported Versions
We actively maintain and provide security updates for the following versions:
| 0.1.x | :white_check_mark: |
## Reporting a Vulnerability
If you discover a security vulnerability within `license-trace`, please do **NOT** open a public issue. Instead, please report it privately:
1. **Security Advisory:** Submit a private advisory via [GitHub Security Advisories](https://github.com/rikutoyamada01/license-trace/security/advisories/new).
2. **Email Contact:** Alternatively, reach out directly to the maintainers at `rikutoyamada01@gmail.com` with the subject tag `[SECURITY] license-trace vulnerability`.
### What to Include in Your Report
- Detailed description of the vulnerability and its potential impact.
- Step-by-step reproduction instructions or a minimal Proof of Concept (PoC).
- Affected ecosystem resolvers (Cargo, npm, PyPI, Go) or CLI commands.
- Any suggested remediations or patches if available.
### Response Commitment
- **Acknowledgment:** Within 48 hours of initial receipt.
- **Assessment & Triage:** Within 5 business days.
- **Patch & Advisory Release:** Coordinated security patch released alongside a public CVE / GitHub Security Advisory.