Skip to content

Security: Aryan-202/clara-core

Security

SECURITY.md

Security Policy

Clara is maintained by Aryan Vishwakarma, and the project takes security seriously.

This document explains how to report vulnerabilities and how the project handles security issues.

Reporting a vulnerability

If you believe you have discovered a security vulnerability in this project, please report it privately and responsibly.

Do not open a public GitHub issue for security-sensitive findings.

Please contact the project owner directly:

When reporting, please include:

  • a clear description of the vulnerability
  • the affected component or behavior
  • the steps to reproduce it
  • any relevant proof of concept or example
  • your preferred contact method for follow-up

Response expectations

The project owner will make reasonable efforts to:

  • acknowledge the report promptly
  • assess the severity and impact of the issue
  • work toward a fix in a timely manner
  • keep the reporter informed as the issue is investigated

The exact timeline may vary depending on the complexity of the report and the availability of the maintainer.

Disclosure policy

Security reports should be handled privately until the issue has been investigated and a reasonable mitigation or fix is available.

Please do not disclose the vulnerability publicly before coordination with the project owner has taken place.

Supported versions

The project is actively maintained on the current primary branch and on the versions that remain in active development. Older or unsupported versions may not receive security updates.

If a fix is released, the project owner may identify which versions are affected and whether a patch or workaround is available.

Responsible disclosure

We appreciate responsible disclosure and thank security researchers and contributors who help keep the project safe. Your cooperation helps protect users and maintain trust in the software.

If you are unsure whether something qualifies as a security issue, contact the project owner before disclosing details publicly.

There aren't any published security advisories