We release patches for security vulnerabilities. Currently supported versions:
| Version | Supported |
|---|---|
| 0.3.x | ✅ |
| < 0.3 | ❌ |
We take security seriously. If you discover a security vulnerability, please follow these steps:
Instead:
-
Email nitishagar@gmail.com with:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if available)
-
Allow up to 48 hours for initial response
-
Work with maintainers to verify and fix
- Acknowledgment within 48 hours
- Assessment and triage within 1 week
- Fix development and testing
- Coordinated disclosure after patch release
- Report received: We acknowledge within 48 hours
- Verified: We confirm the vulnerability exists
- Fixed: Patch developed and tested
- Released: Security patch published
- Announced: Public disclosure with credit
- Keep the application updated to the latest version
- Store API keys securely (the app encrypts them locally)
- Keep dependencies updated:
npm audit fix - Only enter API keys from trusted LLM providers
Never commit:
- .env files
- Credentials or API keys
- Certificates or private keys
API keys for Ollama Cloud and OpenAI are stored locally using electron-store with encryption. Keys are:
- Never transmitted except to the configured LLM provider
- Stored in the user's app data directory
- Not included in audit reports or logs
Playwright visits external websites during audits:
- Runs in isolated browser contexts per audit
- No persistent storage of credentials
- Sandboxed execution environment
Subscribe to security advisories:
- GitHub Security Advisories
- Watch this repository
- Check CHANGELOG.md regularly
- Security issues: nitishagar@gmail.com
- General issues: GitHub Issues