# Security policy

`mooncov` parses untrusted coverage and diff text but does not execute it.
Please still treat paths and rendered reports as untrusted when embedding them
in a larger system.

To report a potential denial-of-service issue, path-handling flaw, output
injection, or other vulnerability, open a private security advisory in the
GitHub repository. If private advisories are unavailable, contact the
maintainer through the profile linked by the repository owner. Do not include
secrets, credentials, or private source code in a public issue.

Security fixes are supported for the latest released version.
