Notehold is an early-stage project. Security fixes are provided for the latest released version only.
| Version | Supported |
|---|---|
| Latest release | Yes |
| Older releases | No |
Before reporting a vulnerability, please confirm that it is still present in the latest release.
Please do not report security vulnerabilities in a public GitHub issue, discussion, or pull request.
Email security reports to notehold@googlegroups.com. Include:
- A description of the vulnerability and its potential impact
- The affected Notehold version and macOS version
- Steps or a minimal example that reproduces the problem
- Any suggested mitigation, if known
If you do not receive an acknowledgement within seven days, you may open a public issue asking the maintainer to check the security-reporting inbox. Do not include vulnerability details in that issue.
You should receive an acknowledgement within seven days. After the report is reviewed, the maintainer will share whether it is accepted, what the next steps are, and whether a coordinated disclosure date is appropriate. Please allow time for a fix to be prepared before publishing details.
Reports involving unauthorized access to Apple Notes data, unsafe archive creation or cleanup, command injection, privilege or Full Disk Access misuse, installer or update tampering, and exposure of sensitive paths or log contents are especially useful.
General feature requests, installation questions, and non-security bugs can be reported through the repository's public issue tracker.