# Security Policy

## Reporting a Vulnerability

If you discover a security vulnerability in lintlang, please report it responsibly.

**Do not open a public issue for security vulnerabilities.**

Instead, email us at: **roli@hermes-labs.ai**

Include:
- A description of the vulnerability.
- Steps to reproduce the issue.
- Any relevant logs or output.

## Response Timeline

- **Acknowledgment**: Within 48 hours of your report.
- **Assessment**: Within 7 days we will confirm the issue and outline next steps.
- **Fix**: We aim to release a patch within 30 days of confirmation.

## Supported Versions

Security updates are applied to the latest release only.

Thank you for helping keep lintlang safe.

