Skip to content

Security: ni5arga/protestchat

SECURITY.md

Security Policy

Supported versions

protestchat is pre-alpha and unaudited. Treat every build as experimental. Fixes land on main.

Reporting a vulnerability

Please do not file a public GitHub issue for security bugs that could put users at risk in the field (crypto, mesh relay abuse, identity spoofing, wipe failures, etc.).

Prefer one of:

  1. GitHub Security AdvisoriesReport a vulnerability on this repository (private to maintainers).
  2. If advisories are unavailable, contact the maintainer @ni5arga privately and say you have a security report — do not paste exploit details in a public issue or PR.

Include:

  • What is affected (file/area if known)
  • Impact in plain language (who gets hurt, under what assumptions)
  • Steps to reproduce or a minimal proof of concept
  • Whether you plan to disclose on a timeline

We will acknowledge receipt when we can and work with you on a fix before public disclosure when that is safer for users.

Non-security bugs

Use a normal GitHub issue with the bug template.

There aren't any published security advisories