GuideArch is on the v1.x release line. Only the most recent minor version on the main branch receives security fixes. Pre-1.0 milestone tags (v0.0.0-bootstrap (M0) through v0.4.0-m4 (M4)) are historical and not patched.
Please report security issues privately by emailing kaveh.razavi@gmail.com with the subject line [guidearch security].
Do not open a public GitHub issue for security reports.
You can expect:
- Acknowledgement within 72 hours.
- An initial assessment within one week.
- A coordinated disclosure timeline once the issue is understood.
Thank you for helping keep GuideArch and its users safe.