# Security policy ## Reporting a vulnerability Do not open a public issue for an exploitable vulnerability or include exploit details in Discord, logs, screenshots, or pull requests. Use [GitHub private vulnerability reporting](https://github.com/sky-systems/sky_phone/security/advisories/new). If that form is unavailable, use the private contact listed on the [official Sky-Systems contact page](https://www.sky-systems.net/impressum). Include the affected release tag or commit, framework and integration context, impact, minimal reproduction, and any proposed mitigation. Remove credentials, tokens, private server addresses, and player-identifying data. We will acknowledge the report, reproduce and assess the impact, coordinate a fix, and publish details after affected users have a reasonable update path. Please do not disclose the issue publicly before that coordination is complete. ## Supported versions Security fixes target the latest published release and the current `dev` branch. Older releases may require upgrading before a fix can be applied.