# Security policy Security fixes are provided for the latest published WRNexusJS minor release. Keep every `@wrnexus/*` package on the same version and run `wrnexus update` before reporting an issue. Do not open a public issue for a suspected vulnerability. Use the repository's private security reporting channel and include the affected package/version, reproduction, impact, and suggested mitigation. Never include production credentials or personal data. Deployments must use HTTPS, keep secrets outside source control, configure trusted proxies and origins explicitly, and review the package security notes for auth, CAPTCHA, encryption, uploads, OAuth, JWT, and database adapters.