Security fixes are applied to the latest released version of Arcovia.
Please do not open a public issue for a suspected vulnerability. Use this repository's Security tab and select Report a vulnerability to submit a private GitHub vulnerability report.
If private vulnerability reporting is not enabled in the repository settings, please wait for that private channel to be enabled rather than publishing exploit details in a public issue.
Include:
- affected version and environment;
- reproduction steps or a proof of concept;
- potential impact;
- any suggested mitigation.
Reports are reviewed as promptly as possible. Arcovia analyses local source trees and generates reports, so reports involving unintended file access, unsafe report rendering, path handling, or secret exposure are especially valuable.
Please do not include secrets or proprietary source files unless they are essential to reproduce the issue.
Please give maintainers reasonable time to investigate and release a fix before publicly disclosing a vulnerability. Once a fix is available, the report may be published as a GitHub security advisory with appropriate acknowledgement where requested.