Skip to content

Latest commit

 

History

History
44 lines (21 loc) · 1.98 KB

SECURITY.md

File metadata and controls

44 lines (21 loc) · 1.98 KB

Security Policy

Security policy of arcane crate (and its arcane-core, arcane-codegen, arcane-codegen-impl and arcane-codegen-shim sub-crates).

Supported versions

Before going 1.0, the arcane crate maintains only the most recent minor release.

Reporting a vulnerability

Security is of the highest importance and all security vulnerabilities or suspected security vulnerabilities should be reported to this project privately, to minimize attacks against current users of arcane crate before they are fixed. Vulnerabilities will be investigated and patched on the next patch (or minor) release as soon as possible. This information could be kept entirely internal to the project.

Private disclosure process

WARNING: Do not file public issues on GitHub for security vulnerabilities.

To report a vulnerability or a security-related issue, please use GitHub private vulnerability reporting on the Security Advisories page and fill the vulnerability details. It will be addressed within a week, including a detailed plan to investigate the issue and any potential workarounds to perform in the meantime. Do not report non-security-impacting bugs through this channel, use GitHub issues instead.

Public disclosure process

Project maintainers publish a public advisory to the community via GitHub.