Aldus is public beta software. Security fixes are made against the latest published release; older beta releases are not maintained separately. Upgrade to the latest release before reporting a problem that may already be fixed.
Use GitHub's private vulnerability reporting. Do not disclose a vulnerability in a public issue, Discussion, pull request, or social post before a fix is available.
Include, when available:
- The affected Aldus version and component.
- The impact and conditions required to reproduce it.
- Minimal reproduction steps or a proof of concept.
- Any suggested mitigation.
Do not include real passwords, tokens, personal library data, or copyrighted media. Use clearly marked test values instead.
You will receive acknowledgement when a maintainer reviews the report. Timelines depend on severity and maintainer availability; please allow time to investigate and coordinate disclosure.