Security fixes are applied to the latest published ReviewArc release and the
current main branch. Older beta builds may require upgrading to receive a fix.
Do not open a public issue, discussion, or pull request for a suspected
vulnerability. Use GitHub's Report a vulnerability form in the repository's
Security tab. If private vulnerability reporting is unavailable, email
stran58@gmail.com with the subject ReviewArc security report.
Include the affected version or commit, reproduction steps, expected impact, and any suggested mitigation. Remove credentials, private repository contents, and personal data from the report unless they are essential; coordinate a safe transfer before sending sensitive material.
The maintainer will acknowledge a complete report as soon as practical, investigate it privately, and coordinate disclosure after a fix or mitigation is available. Please do not disclose the issue publicly before that coordination is complete.