Skip to content

Security: TynK-M/zarko

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

We take the security of Zarko seriously.

If you believe you have found a security vulnerability in Zarko, please do not open a public GitHub issue.

Instead, report the vulnerability privately so that we can investigate and address it before the details become public.

Please include as much of the following information as possible:

  • A description of the vulnerability.
  • Steps to reproduce the issue.
  • A minimal proof of concept, if available.
  • The affected version of Zarko.
  • The expected and actual behavior.
  • The potential impact of the vulnerability.
  • Any possible mitigations or workarounds you are aware of.

Reporting Contact

Please report security vulnerabilities through the project's GitHub Security Advisories:

https://github.com/TynK-M/zarko/security/advisories/new

If GitHub Security Advisories are not available, contact the project maintainers privately through GitHub.

What to Expect

After submitting a security report:

  1. We will review the report and attempt to reproduce the issue.
  2. We may contact you for additional information.
  3. If the vulnerability is confirmed, we will work on a fix and determine the appropriate release.
  4. We will coordinate disclosure of the vulnerability once a fix or mitigation is available.

Please allow maintainers reasonable time to investigate and address reported vulnerabilities before publicly disclosing them.

Supported Versions

Security fixes are generally provided for the latest supported version of Zarko.

Version Supported
Latest release
Older releases

If you are using an older version, please upgrade to the latest release before reporting a vulnerability whenever possible.

Responsible Disclosure

Please avoid publicly disclosing vulnerabilities before a fix or mitigation is available.

Do not include sensitive information, credentials, private data, or working exploit details in public issues, discussions, or pull requests.

We appreciate responsible security research and will credit security researchers who report valid vulnerabilities, unless they prefer to remain anonymous.

Thank you for helping keep Zarko and its users safe. 🦎

There aren't any published security advisories