# Security Policy

## Supported Versions

The maintained branches and what each one receives are listed in a single place, [RELEASES.md](RELEASES.md#minor-release-support-matrix),
so that this file cannot drift away from it.

## Reporting a Vulnerability

If you think you have found a security issue, **do not open a public issue**. Report it privately, either way:

- through GitHub private vulnerability reporting, from the [Security tab](https://github.com/web-auth/cose-lib/security/advisories/new) of this repository, or
- by e-mail to **security [at] spomky-labs.com**.

Please include the affected version, a description of the issue and, when possible, a reproduction script. You will
get an acknowledgement of the report, and a fix will be prepared privately before any public disclosure.
