Anarlog moves fast and we only ship fixes forward. Security updates are applied to the latest release only.
If you're on an older version, please update to the latest release before reporting an issue you can no longer reproduce.
Please do not open a public issue for security vulnerabilities.
Instead, use one of these private channels:
- GitHub: Report a vulnerability via private vulnerability reporting (preferred)
- Email: founders@fastrepl.com
When reporting, please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce, a proof of concept, or affected code paths
- The Anarlog version and platform you tested against
- We'll acknowledge your report within 3 business days.
- We'll keep you updated as we investigate, and let you know whether the report is accepted or declined.
- If accepted, we'll work on a fix and credit you in the release notes unless you prefer to stay anonymous.
- Please give us a reasonable window to ship a fix before any public disclosure.
Thanks for helping keep Anarlog and its users safe.
