# Security Policy

## Supported Versions

The following versions will receive security updates.

| Version | Security updates   |
| ------- | ------------------ |
| 1.5.x   | :white_check_mark: |
| 1.4.x   | :white_check_mark: |
| 1.3.x   | :white_check_mark: |
| < 1.3   | :x:                |

## Reporting a Vulnerability

> [!IMPORTANT]
> Please **only** report security vulnerabilities directly relating to the PIE tool itself on this repository.
> This is **NOT** a place where you can report security vulnerabilities for individual extensions.
>
> **If you find a vulnerability in an extension, please locate the appropriate repository/author and reporting policy for that extension. Do NOT report it to PIE, as it will be closed.**

Please do not publicly disclose security vulnerabilities.

If you discover something that you think may be a vulnerability, please
[report it **privately** on GitHub](https://docs.github.com/en/code-security/how-tos/report-and-fix-vulnerabilities/privately-reporting-a-security-vulnerability).

 * Go to the [Security and Quality](https://github.com/php/pie/security) tab in the PIE repository.
 * Click **Report a vulnerability** and fill in the form with as much information as possible.
 * Hit submit, and we'll look into it as soon as possible.

Thank you for responsibly disclosing issues in PIE 🥧
