# Security Policy ## Supported versions Until tagged releases are published, only the current default branch receives security fixes. Supported release versions will be listed here once releases begin. ## Reporting a vulnerability Do not open a public issue for a suspected vulnerability. Contact the maintainer through an established private channel and include the affected commit or version, impact, reproduction steps, and any suggested mitigation. If you do not have a private contact method, ask for one in an issue without disclosing vulnerability details. Do not include real SNMP credentials, `.env`, `config.ini`, `state.json`, controller addresses, AP names, or unredacted logs. Reports will be acknowledged and updated on a best-effort basis; please allow time for a fix before public disclosure.