Skip to content

Security: everettjf/grapecompare

SECURITY.md

Security Policy

Supported versions

Security fixes are provided for the latest released version of GrapeCompare.

Version Supported
1.1.x Yes
1.0.x and earlier No

Report a vulnerability

Please use GitHub's private Report a vulnerability form. Do not disclose a suspected vulnerability in a public issue, pull request, or discussion.

Include the affected version, macOS version, impact, reproduction steps, and a minimal proof of concept when safe to share. Remove unrelated personal or confidential data.

You should receive an acknowledgement within seven days. After validation, the maintainer will coordinate a fix and disclosure timeline with you. Please allow a reasonable remediation period before public disclosure.

Scope

Security reports include unintended filesystem access, sandbox escapes, unsafe parsing, data disclosure, and supply-chain concerns. Ordinary crashes, comparison correctness bugs, and feature requests can use the public issue tracker.

There aren't any published security advisories