Arras is actively maintained. Security updates and patches are provided for the latest major versions as outlined below.
| Version | Supported |
|---|---|
| 2.x.x | ✅ |
| 1.x.x | ❌ |
| < 1.0 | ❌ |
We take the security of Arras seriously. If you discover a security vulnerability, please report it privately to ensure it can be addressed safely before public disclosure.
How to Report:
- Please use the Private Vulnerability Reporting feature on this GitHub repository, OR
- Send a direct message/email to the maintainer with a clear description of the issue and steps to reproduce.
What to Expect:
- Acknowledgement: You can expect an initial response acknowledging your report within 48 hours.
- Triage: We will investigate the issue and confirm whether it is a valid vulnerability.
- Resolution: If accepted, we will work promptly to develop and release a patch. You will be credited in the release notes for your responsible disclosure. If declined, we will provide a clear technical explanation as to why.
Please do not open public issues for security vulnerabilities.