Skip to content

Security: TheRemyyy/arden-lang

SECURITY.md

Security Policy

Supported Versions

Arden follows a rolling support model:

  • master: supported for security fixes
  • Latest tagged release (v*): supported for security fixes
  • Older releases: best effort only

Reporting a Vulnerability

Please do not open public GitHub issues for potential vulnerabilities.

Report privately via GitHub Security Advisories:

  1. Open the repository's Security tab.
  2. Click Report a vulnerability.
  3. Provide:
    • affected version/commit
    • impact and attack scenario
    • minimal reproduction (if possible)
    • proposed mitigation (optional)

Response Targets

  • Initial triage response: within 3 business days
  • Remediation plan/decision: within 7 business days
  • Fix release timing: depends on severity and exploitability

Disclosure

Coordinated disclosure is preferred. We will credit reporters unless anonymity is requested.

There aren't any published security advisories