# Security Policy

## Supported Versions

We only provide security updates for the latest 2.x release line.

| Version | Supported |
| ------- | --------- |
| 2.x     | :white_check_mark: |
| < 2.0   | :x: |

## Reporting a Vulnerability

Please report security issues privately.

- Preferred: open a GitHub Security Advisory (Security tab → “Report a vulnerability”).
- Email: security@pontedilana.it

What to include:
- A clear description and impact
- A minimal reproducer (code/config) if possible
- Affected versions and environment details

We aim to acknowledge reports within **5 business days** and will follow up with an assessment and next steps. If the issue is accepted, we will coordinate a fix and disclose after a patch is available.
