# Security Policy ## Supported Versions |Version|Supported| |-------|---------| | 5.x | ✅ Yes | | < 5.0 | ❌ No | --- ## Reporting a Vulnerability If you discover a security vulnerability, **do not open a public issue**. Instead: 1. **Email** your report to [security@krz.sh](mailto:security@krz.sh). Include: - A detailed description of the vulnerability - Steps to reproduce - Any relevant context (e.g., affected versions, environment) 2. **Response Time**: We will acknowledge your report within **3 business days** and keep you updated on the progress. 3. **Resolution**: If confirmed, we will: - Provide an estimated timeline for a fix - Work with you to verify the resolution - Credit you for the discovery (if you wish) 4. **Declined Reports**: If the report is invalid or out of scope, we will explain why and close the issue. --- **Thank you for helping improve the security of our project!**