# Security Policy [简体中文](SECURITY.zh-CN.md) | English ## Supported Versions Security updates are provided for the latest EasyTier release. Before reporting a vulnerability, please verify it against the latest release or the current `main` branch when practical. | Version | Supported | | --- | --- | | Latest release | Yes | | Older releases | No | ## Reporting a Vulnerability Please report suspected vulnerabilities through GitHub's [private vulnerability reporting form](https://github.com/EasyTier/EasyTier/security/advisories/new). Do not disclose the vulnerability in a public issue, discussion, or pull request. A useful report should include: - the affected EasyTier version or commit; - the affected platform and relevant configuration, with secrets removed; - a description of the vulnerability and its potential impact; - reproducible steps or a minimal proof of concept; and - any known mitigations or workarounds. The maintainers will assess the report and coordinate remediation and disclosure through the private advisory. Please allow reasonable time for a fix before publishing details. When investigating, avoid accessing or modifying other users' data, disrupting services, or violating applicable laws.