Reporting a vulnerability

Please do not open a public GitHub issue for security reports. Use one of the private channels below.

Please include:

Response timeline

This is a volunteer-maintained open-source project. We do our best to respond promptly, but timelines may vary:

Acknowledgment
As soon as possible.
Fix or mitigation
Depends on severity and complexity.

Supported versions

Ariadne is in beta. Until we reach GA, only the latest published release receives security fixes — older versions will not be patched. Upgrade to the most recent 0.x release on Maven Central to stay covered.

Scope

Ariadne is a client-side Spark library that reads and writes index data to a Hadoop-accessible filesystem. Security concerns most likely to be relevant include:

Disclosure policy

We follow coordinated disclosure. Once a fix is available, we will:

  1. Release a patched version.
  2. Publish a security advisory on GitHub.
  3. Credit the reporter (unless they prefer to remain anonymous).