# Security Policy DNSControl is a command-line tool and therefore has a different (limited) attack surface as compared to a web app or other system. ## Supported Versions Only the most recent release is supported with security updates. When a major version is incremented, we'll support the previous major version for 6 months. For example, when v4.0 is released, we will support the most recent v3.x release for 6 months. ## Reporting a Vulnerability To report a vulnerability please [create a new GitHub "issue"](https://github.com/StackExchange/dnscontrol/issues/new/choose). We will respond in a best-effort manner, usually within 1 week. We will communciate via the GitHub issue unless we need to communicate privately, in which case we'll arrange a way to communicate directly.