Skip to content

Security: ryanrborn/arbiter

Security

SECURITY.md

Security Policy

Supported Versions

Arbiter does not yet publish versioned releases with parallel maintenance branches. Security fixes are made against the latest commit on main, which is the only supported version at this time.

Version Supported
main ✅
Other ❌

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Instead, report vulnerabilities privately using GitHub's private vulnerability reporting feature for this repository. This opens a private advisory visible only to the maintainer and lets you submit details, and later a fix, without exposing the issue publicly before it's resolved.

Please include as much of the following as you can:

  • A description of the vulnerability and its potential impact.
  • Steps to reproduce, or a proof-of-concept.
  • The affected commit, file(s), or component.
  • Any suggested mitigation, if you have one.

You should expect an initial response within 5 business days. If the report is confirmed, a fix will be prioritized and coordinated with you before any public disclosure, including credit in the advisory if you'd like it.

There aren't any published security advisories