# Security Policy

## Supported Versions

Updates are provided according to table below.

| Version | Security Updates   |  Feature Updates   |  Bug Fixes         |
| ------- | ------------------ | ------------------ | ------------------ |
| 4.1.x   | :white_check_mark: | :white_check_mark: | :white_check_mark: |
| 4.0.x   | :white_check_mark: | :x:                | :x:                |
| 3.6.x   | :white_check_mark: | :x:                | :x:                |
| 3.5.x   | :x:                | :x:                | :x:                |
| 3.4.x   | :x:                | :x:                | :x:                |
| < 4.0   | :x:                | :x:                | :x:                |

## Reporting a Vulnerability

If you discover any security related issues, please email hello@tabacitu.ro instead of using the issue tracker.

## Past Vulnerabilities

Since its inception in 2016, Backpack has had zero security breaches or reported security issues. However, its dependencies _have_ had security flaws discovered and fixed - even major ones like Laravel, Bootstrap and jQuery. That's why it's a good idea for any project to be reasonably up-to-date. If we consider a security issue is something that affects our users, we'll email you. 

It's _heavily_ recommended that you **[subscribe to the Backpack Newsletter](http://backpackforlaravel.com/newsletter)** so you can find out about any security updates, breaking changes or major features. We send an email about 1-2 emails per year. Sometimes less.
