We take the security of Zarko seriously.
If you believe you have found a security vulnerability in Zarko, please do not open a public GitHub issue.
Instead, report the vulnerability privately so that we can investigate and address it before the details become public.
Please include as much of the following information as possible:
- A description of the vulnerability.
- Steps to reproduce the issue.
- A minimal proof of concept, if available.
- The affected version of Zarko.
- The expected and actual behavior.
- The potential impact of the vulnerability.
- Any possible mitigations or workarounds you are aware of.
Please report security vulnerabilities through the project's GitHub Security Advisories:
https://github.com/TynK-M/zarko/security/advisories/new
If GitHub Security Advisories are not available, contact the project maintainers privately through GitHub.
After submitting a security report:
- We will review the report and attempt to reproduce the issue.
- We may contact you for additional information.
- If the vulnerability is confirmed, we will work on a fix and determine the appropriate release.
- We will coordinate disclosure of the vulnerability once a fix or mitigation is available.
Please allow maintainers reasonable time to investigate and address reported vulnerabilities before publicly disclosing them.
Security fixes are generally provided for the latest supported version of Zarko.
| Version | Supported |
|---|---|
| Latest release | ✅ |
| Older releases | ❌ |
If you are using an older version, please upgrade to the latest release before reporting a vulnerability whenever possible.
Please avoid publicly disclosing vulnerabilities before a fix or mitigation is available.
Do not include sensitive information, credentials, private data, or working exploit details in public issues, discussions, or pull requests.
We appreciate responsible security research and will credit security researchers who report valid vulnerabilities, unless they prefer to remain anonymous.
Thank you for helping keep Zarko and its users safe. 🦎