Skip to content

Security: rsheyd/notehold

SECURITY.md

Security Policy

Supported versions

Notehold is an early-stage project. Security fixes are provided for the latest released version only.

Version Supported
Latest release Yes
Older releases No

Before reporting a vulnerability, please confirm that it is still present in the latest release.

Reporting a vulnerability

Please do not report security vulnerabilities in a public GitHub issue, discussion, or pull request.

Email security reports to notehold@googlegroups.com. Include:

  • A description of the vulnerability and its potential impact
  • The affected Notehold version and macOS version
  • Steps or a minimal example that reproduces the problem
  • Any suggested mitigation, if known

If you do not receive an acknowledgement within seven days, you may open a public issue asking the maintainer to check the security-reporting inbox. Do not include vulnerability details in that issue.

You should receive an acknowledgement within seven days. After the report is reviewed, the maintainer will share whether it is accepted, what the next steps are, and whether a coordinated disclosure date is appropriate. Please allow time for a fix to be prepared before publishing details.

Scope

Reports involving unauthorized access to Apple Notes data, unsafe archive creation or cleanup, command injection, privilege or Full Disk Access misuse, installer or update tampering, and exposure of sensitive paths or log contents are especially useful.

General feature requests, installation questions, and non-security bugs can be reported through the repository's public issue tracker.

There aren't any published security advisories