Security reports are accepted for the main branch and for commits pointed to by an existing tag.
Do not report security issues through our public issue tracker on GitHub or git.mari.zip.
Prefer the following channels:
- GitHub Security Advisory
- Via email to
gitarena_security <at> mari.zip.
We prefer communications to be in english.
We explicitly allow AI-assisted findings.
If AI tooling has been used to discover, analyze or write up the issue, please state so clearly in your report.
We will still take your report seriously and investigate thorougly but disclosing upfront helps maintainers calibrate how much additional verification a report needs.
- We will acknowledge your security report within a week.
- During testing, assessment and investigation you will receive regular updates.
- After a vulnerability has been confirmed, we will issue a fix within a week. As GitArena is fully open-source, we consider the vulnerability to be public from that point onward.
- The vulnerability report is prepared for publishing and released within 90 days. We will credit you unless you'd prefer to stay anonymous.