Arbiter does not yet publish versioned releases with parallel maintenance
branches. Security fixes are made against the latest commit on main, which
is the only supported version at this time.
| Version | Supported |
|---|---|
main |
✅ |
| Other | ❌ |
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, report vulnerabilities privately using GitHub's private vulnerability reporting feature for this repository. This opens a private advisory visible only to the maintainer and lets you submit details, and later a fix, without exposing the issue publicly before it's resolved.
Please include as much of the following as you can:
- A description of the vulnerability and its potential impact.
- Steps to reproduce, or a proof-of-concept.
- The affected commit, file(s), or component.
- Any suggested mitigation, if you have one.
You should expect an initial response within 5 business days. If the report is confirmed, a fix will be prioritized and coordinated with you before any public disclosure, including credit in the advisory if you'd like it.