This is the default security policy for all ArcavenAE repositories. A repository with its own SECURITY.md overrides this one.
If you discover a security vulnerability in any ArcavenAE project, please
report it privately using GitHub's vulnerability reporting: open the
repository's Security tab and choose Report a vulnerability
(https://github.com/ArcavenAE/<repo>/security/advisories/new).
Please include:
- Description of the vulnerability
- Steps to reproduce
- Your assessment of severity
We will respond within two weeks to acknowledge the report and coordinate a fix.
Please keep the report confidential until a patch is available.