If you believe you have found a security vulnerability in z4j-arq,
do not open a public GitHub issue. Email security@z4j.com instead.
We acknowledge reports within 48 hours, provide a preliminary assessment within 5 business days, and target fixes within 30 days (7 days for confirmed critical issues). Reporting timelines, safe harbor, supported-version policy, and published advisories are maintained in the canonical z4j project security policy.
This adapter runs inside arq workers with their Redis access. An authenticated
brain can submit and cancel jobs through the advertised controls. Function-name
selection, task argument handling, Redis calls, and lifecycle-event mapping are
package-specific security surfaces; transport, redaction, and authorization
policy remain owned by z4j-core and the brain.