# Security policy

## Supported versions

Security fixes are applied to the latest published `1.x` release.

## Reporting a vulnerability

Please use [GitHub's private vulnerability reporting form](https://github.com/ElJijuna/vite-legacy-pass-through/security/advisories/new). Do not open a public issue or include credentials, access tokens, or proof-of-concept payloads that could affect third parties.

Include the affected version, a minimal reproduction, impact, and suggested mitigation when possible. Maintainers will acknowledge reports and coordinate a fix privately before disclosure.

## Dependency checks

Run `npm run audit` to check high- and critical-severity dependency advisories. The release workflow runs the same command before publishing.
