Skip to content

Security: getaskclaw/xarc

Security

SECURITY.md

XArc Security Policy

Supported version

Security fixes are currently made on the latest source revision. Until a stable release policy is published, older snapshots may not receive fixes.

Reporting a vulnerability

Do not include private archive content in a public issue. In particular, do not attach or paste:

  • extracted archive files or media;
  • config.local.json or private paths;
  • generated SQLite databases, lock/sidecar files, summaries, inventories, or exports;
  • post/account identifiers, direct messages, contacts, security records, access tokens, or other personal data.

Prepare a minimal reproduction with a synthetic archive and redact local usernames and filesystem paths. If sensitive details are essential, use this placeholder only after maintainers replace it with a real private channel:

Private report destination: <maintainer-provided private security contact>

Until such a destination is published, open a public issue containing only a sanitized summary and ask maintainers how to continue privately. Do not send private data to an unverified address or URL.

Reports should state the affected revision, platform and Python version, impact, reproduction steps, and any proposed mitigation. Archive read-only boundary bypasses, unsafe export/index publication, private-content indexing, and credential disclosure should be treated as security issues.

There aren't any published security advisories