Evidence-backed facts
- Arrow defines language-independent columnar and IPC representations and documents security considerations for standardized serialized data. informative
- Serialized Arrow from untrusted sources should be structurally and semantically validated before use because invalid buffers or metadata can cause unsafe access. informative
- Published arrays must not leak uninitialized buffer contents, and extension metadata deserialization must reject malformed or malicious payloads safely. informative
- The C Data Interface contains process pointers and cannot safely accept an untrusted producer; format compatibility alone is not authentication, authorization, or data-truth evidence. informative