Ryoku is a rolling Arch Linux distribution under active development. Security fixes target the current development branch and the latest release. Always reproduce a report against an up-to-date checkout or the most recent ISO before filing.
Please report security issues privately. Do not open a public issue, pull request, or discussion for a vulnerability.
- Preferred: open a private report through GitHub at Security > Report a vulnerability.
- Alternative: contact the maintainer privately at github.com/neur0map.
Include enough detail to reproduce:
- What the issue is and the impact you observed.
- Affected component (installer, system, or a specific part of the desktop) and the version, ISO date, or commit.
- Steps to reproduce, and a proof of concept if you have one.
- Any suggested fix or mitigation.
- We aim to acknowledge a report within a few days.
- We will confirm the issue, assess the impact, and keep you updated on progress.
- Once a fix is ready, we will release it and credit you if you wish.
Please give us reasonable time to investigate and ship a fix before any public disclosure. Thank you for helping keep Ryoku users safe.