Skip to content

Security: ejames-dev/SubSync

Security

SECURITY.md

Security Policy

Supported Versions

SubSync is a local-first desktop application. Security fixes are provided for the current minor release line.

Version Supported
1.1.x Yes
< 1.1 No

Reporting a Vulnerability

Please report suspected vulnerabilities privately through GitHub Security Advisories for this repository. Do not open a public issue for security-sensitive reports.

Include as much detail as you can safely share:

  • A description of the vulnerability and affected feature.
  • Steps to reproduce or a minimal proof of concept.
  • The impacted platform and SubSync version.
  • Any known workaround or mitigation.

You can expect an initial response within 7 days. Accepted reports will be tracked privately until a fix or mitigation is available, then disclosed in the release notes when appropriate. If a report is declined, the response will explain why it is not considered a security issue for SubSync.

There aren't any published security advisories