Skip to content

Security: Cratis/Arc.TypeScript

Security

SECURITY.md

Security policy

Report a vulnerability privately

Do not report a suspected vulnerability in a public GitHub issue, pull request, or discussion.

Email oss@cratis.io with Security: at the start of the subject. Include:

  • the repository (Cratis/Arc.TypeScript) and the exact commit, or the package and version once packages exist;
  • what you observed and what you expected;
  • minimal reproduction steps and the conditions needed to reach the behavior;
  • the potential impact as you understand it; and
  • a safe way to contact you for follow-up.

Leave credentials, personal data, customer data, and production logs out of the first message. Ask for a private transfer method if more evidence is needed.

Supported versions

This project is an early source preview, with no stable release or published npm packages. Reports against the current main branch and the latest GitHub source preview are welcome.

Scope

This policy provides a private reporting route. It is not a response-time commitment, service-level agreement, warranty, or bounty. See the Cratis security policy for the organization-wide terms.

Vulnerabilities in Arc on .NET or in the @cratis/arc client belong to the Arc repository. Use the same private route and name the affected repository.

There aren't any published security advisories