SubSync is a local-first desktop application. Security fixes are provided for the current minor release line.
| Version | Supported |
|---|---|
| 1.1.x | Yes |
| < 1.1 | No |
Please report suspected vulnerabilities privately through GitHub Security Advisories for this repository. Do not open a public issue for security-sensitive reports.
Include as much detail as you can safely share:
- A description of the vulnerability and affected feature.
- Steps to reproduce or a minimal proof of concept.
- The impacted platform and SubSync version.
- Any known workaround or mitigation.
You can expect an initial response within 7 days. Accepted reports will be tracked privately until a fix or mitigation is available, then disclosed in the release notes when appropriate. If a report is declined, the response will explain why it is not considered a security issue for SubSync.