Skip to content

Security: yashashwi-s/Arras

SECURITY.md

Security Policy

Supported Versions

Arras is actively maintained. Security updates and patches are provided for the latest major versions as outlined below.

Version Supported
2.x.x
1.x.x
< 1.0

Reporting a Vulnerability

We take the security of Arras seriously. If you discover a security vulnerability, please report it privately to ensure it can be addressed safely before public disclosure.

How to Report:

  1. Please use the Private Vulnerability Reporting feature on this GitHub repository, OR
  2. Send a direct message/email to the maintainer with a clear description of the issue and steps to reproduce.

What to Expect:

  • Acknowledgement: You can expect an initial response acknowledging your report within 48 hours.
  • Triage: We will investigate the issue and confirm whether it is a valid vulnerability.
  • Resolution: If accepted, we will work promptly to develop and release a patch. You will be credited in the release notes for your responsible disclosure. If declined, we will provide a clear technical explanation as to why.

Please do not open public issues for security vulnerabilities.

There aren't any published security advisories