If you discover a security vulnerability or potential risk in ARGI, please do not disclose details in a public Issue, Discussion, or Pull Request.
Contact one of the project maintainers listed in pom.xml using the
public contact information on their GitHub profile, and ask to establish a
private reporting channel. Do not include vulnerability details until the
maintainer confirms that channel. Once private contact is established, include
as much of the following information as possible:
- The affected module, version, or commit.
- The impact and conditions required to trigger the issue.
- Reproduction steps, a minimal reproduction, or relevant logs.
- Any suggested remediation, if available.
Maintainers will assess the impact after confirming the issue and coordinate the fix, release, and disclosure timeline.
Please do not publicly disclose vulnerability details before maintainers have confirmed and addressed the issue. We aim to handle security reports responsibly while protecting users.