Security Policy
How to report security issues in Ariadne and what to expect from the maintainer in response.
Reporting a vulnerability
Please do not open a public GitHub issue for security reports. Use one of the private channels below.
- GitHub: Report a security advisory (preferred).
- Email: ariadne-support@cjfravel.dev with subject
[SECURITY] <brief description>.
Please include:
- A description of the vulnerability
- Steps to reproduce, if applicable
- The potential impact
- Any suggested fixes
Response timeline
This is a volunteer-maintained open-source project. We do our best to respond promptly, but timelines may vary:
- Acknowledgment
- As soon as possible.
- Fix or mitigation
- Depends on severity and complexity.
Supported versions
Ariadne is in beta. Until we reach GA, only the latest published release receives security fixes — older versions will not be patched. Upgrade to the most recent 0.x release on Maven Central to stay covered.
Scope
Ariadne is a client-side Spark library that reads and writes index data to a Hadoop-accessible filesystem. Security concerns most likely to be relevant include:
- Path traversal or injection via index names or file paths
- Deserialization vulnerabilities in metadata parsing (Gson)
- Lock-file manipulation leading to data corruption
Disclosure policy
We follow coordinated disclosure. Once a fix is available, we will:
- Release a patched version.
- Publish a security advisory on GitHub.
- Credit the reporter (unless they prefer to remain anonymous).