This repository is maintained on main.
| Version | Supported |
|---|---|
main |
Yes |
Security-sensitive areas include:
- public privacy and release hygiene
- local telemetry/accounting values shown in the UI
- feeder and DFP control surfaces
- startup/launcher behavior
- copy-only public support links and non-browser-launch behavior
- local-first
- loopback-local
- fail-closed on privacy uncertainty
- no public commit of private paths, usernames, or secrets
Do not post exploit details in a public issue.
Instead:
- Open a private GitHub security advisory, or
- Contact the maintainer directly with:
- reproduction steps
- affected commit or version
- impact summary
- proposed mitigation if available