Skip to content

Security: emergentinteractive/arcade-sdk

SECURITY.md

Security Policy

Supported versions

Security fixes are made for the latest published release. Users should upgrade to the newest version before reporting an issue that may already be resolved.

Version Supported
Latest published release Yes
Older releases No

Reporting a vulnerability

Do not open a public issue, discussion, or pull request for a suspected vulnerability. Use GitHub's private vulnerability reporting to send the report directly to the maintainers.

Please include:

  • the affected SDK version and environment;
  • the security impact and who could be affected;
  • minimal reproduction steps or a proof of concept; and
  • any suggested mitigation, if known.

Maintainers will keep the report private while validating it, coordinate a fix and release when warranted, and credit reporters who request credit. Please allow time for a fix to reach users before publishing details. This project does not promise a bounty or other reward for reports.

There aren't any published security advisories