# Security Policy

## Supported Versions

Due to both time and resource constrains the Highlight.js core team only fully supports the current major/minor release of the library.  Problems with minor releases are often resolved by upgrading to the most recent release.

| Version  | Supported  | Status  |
| :-----:  | :-: | :------ |
| 10.6.0   | :white_check_mark: &nbsp; :closed_lock_with_key: |  The 10.x series recieves regular updates, new features & bug fixes. |
| <= 10.4.0  | :x: | Known vulnerabities.  *Please upgrade to a more recent 10.x release.* |
| 9.18.5   | :x: |  [EOL](https://github.com/highlightjs/highlight.js/issues/2877). No longer supported. See [VERSION_10_UPGRADE.md](https://github.com/highlightjs/highlight.js/blob/master/VERSION_10_UPGRADE.md). |
| <= 9.18.3 | :x: | No longer supported.  Known vulnerabities. |
| <= 8.x    | :x: | Obsolete. |


## Reporting a Vulnerability

Minor vulnerabilities can simply be reported (and tracked) via our [GitHub issues](https://github.com/highlightjs/highlight.js/issues).   If you feel your issue is more sensitive than that you can always reach us via email: [security@highlightjs.org](mailto:security@highlightjs.org)

