Security Policy
Supported versions and the private GitHub channel for reporting a vulnerability.
VidArch has no deliberate first public Git release yet. Until that exists, security fixes target the current main branch only. Historical or recreated tags are not supported versions.
| Version | Status |
|---|---|
Current main branch | supported |
| Other branch, historical tag or fork | not supported |
The package.json version is 1.0.0; that number is not a published Git tag.
Private reporting
Do not open a public issue for an exploitable vulnerability. Use the GitHub private advisory form. Do not contact the maintainer by personal email.
If private reporting is unavailable, open a minimal public issue asking for a private contact channel. Do not include cookies, downloaded media, private URLs, database contents or other sensitive details.
Include the affected commit or image tag, deployment method, clear reproduction steps and the expected impact. You should receive an acknowledgement within seven days and an initial assessment within fourteen days.
The reference text remains SECURITY.md.