# Security Policy
## Reporting a vulnerability
Please report suspected vulnerabilities privately by emailing
[security@pinprick.rs](mailto:security@pinprick.rs) or using
[GitHub's private vulnerability reporting](https://github.com/starhaven-io/pinprick/security/advisories/new).
Do not open a public issue for an undisclosed vulnerability.
Include the affected component, version, or commit; reproduction steps; potential
impact; and any suggested mitigation. We will acknowledge the report,
investigate it, and coordinate disclosure with you.
Reports about unsafe runtime fetches performed by third-party GitHub Actions
should normally be sent to that action's maintainer; report them here when
pinprick fails to detect or accurately describe the behavior.
## Supported versions
Only the latest released version of pinprick is supported with security fixes.