Developers
Security Policy
Report a vulnerability without exposing users.
The latest release branch of VidArch receives security patches. The 1.x series is currently supported; versions prior to 1.0 are not supported.
Private Reporting
Do not open a public issue for an exploitable vulnerability. Use a GitHub Security Advisory draft in the repository's Security tab, or contact the maintainer via their GitHub profile.
Include:
- a description and the impact;
- reproduction steps or a minimal proof of concept;
- the affected versions;
- a proposed fix, if you have one.
Remove passwords, cookies, private addresses, databases, and media from any examples. Allow the maintainer time to coordinate a fix before publication.