Skip to content

Security: dapome/token

Security

SECURITY.md

Security Policy

Supported Versions

Token is early-stage software. Security fixes are generally applied to the latest commit on main.

Reporting a Vulnerability

Please do not open a public GitHub issue for suspected security vulnerabilities.

Instead, use this private channel:

  • Open a private vulnerability report through GitHub Security Advisories for this repository.

Please include:

  • a clear description of the issue
  • steps to reproduce
  • potential impact
  • any proof-of-concept details (if available)

You can expect an initial response within 5 business days when a report includes enough detail to reproduce.

Scope Notes

When reporting, assume:

  • this app is a local macOS menu bar utility
  • provider credentials are intended to stay in Keychain only
  • no secrets should be included in issues, logs, or screenshots

There aren't any published security advisories