protestchat is pre-alpha and unaudited. Treat every build as experimental. Fixes land on main.
Please do not file a public GitHub issue for security bugs that could put users at risk in the field (crypto, mesh relay abuse, identity spoofing, wipe failures, etc.).
Prefer one of:
- GitHub Security Advisories — Report a vulnerability on this repository (private to maintainers).
- If advisories are unavailable, contact the maintainer @ni5arga privately and say you have a security report — do not paste exploit details in a public issue or PR.
Include:
- What is affected (file/area if known)
- Impact in plain language (who gets hurt, under what assumptions)
- Steps to reproduce or a minimal proof of concept
- Whether you plan to disclose on a timeline
We will acknowledge receipt when we can and work with you on a fix before public disclosure when that is safer for users.
Use a normal GitHub issue with the bug template.