We take the security of ARES seriously. If you discover a vulnerability, we ask that you report it to us responsibly and confidentially. Please do not create a public GitHub issue for security-related matters.
Instead, please send an email with the following information to TODO: your-email@example.com:
- Description of the vulnerability: Explain the nature of the security flaw and how it could potentially be exploited.
- Steps to reproduce: Provide clear, step-by-step instructions to reproduce the issue. Include code examples, configurations, or screenshots that can help us understand and verify the problem.
- Affected versions: Specify which version of ARES you found the vulnerability in.
We will review your report and keep you updated on our progress. Our goal is to address and fix the vulnerability as quickly as possible.
We accept vulnerability reports for the following versions of ARES:
- The latest stable release
- The latest beta or development version (if applicable)
Reports for older, unsupported versions will not be addressed.
For all other issues that are not security-related (e.g., crashes, unexpected behavior, or general errors), please open a new issue on GitHub with the bug label. You can use our Bug Report Template to provide us with the necessary information.