| Version | Supported |
|---|---|
| latest | ✅ |
If you discover a security vulnerability in vens, please report it responsibly:
- Do not open a public GitHub issue
- Email the maintainers or use GitHub's private vulnerability reporting
- Include steps to reproduce the vulnerability
- Allow reasonable time for a fix before public disclosure
We aim to acknowledge reports within 48 hours and provide a fix timeline within 7 days.
- Dependencies are regularly updated via Dependabot
- Code is scanned with CodeQL on every PR
- OpenSSF Scorecard monitors security posture