- [Security Policy](#security-policy) - [Supported Versions](#supported-versions) - [Reporting a Vulnerability](#reporting-a-vulnerability) # Security Policy ## Supported Versions We release patches for security vulnerabilities. Which versions are eligible to receive such patches depend on the CVSS v3.0 Rating: | CVSS v3.0 | Supported Versions | | --------- | -------------------------------------------------- | | 7.3 | 3.3.5 | | 9.8 | 3.3.6 | ## Reporting a Vulnerability Please report (suspected) security vulnerabilities to **[jekkos@opensourcepos.org](mailto:jekkos@opensourcepos.org)**. You will receive a response from us within 48 hours. If the issue is confirmed, we will release a patch as soon as possible depending on complexity but historically within a few days.