Skip to content

Security: hibbault/relay

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x

Reporting a Vulnerability

We take security seriously. If you discover a security vulnerability in Relay, please report it responsibly.

How to Report

Please do NOT open a public GitHub issue for security vulnerabilities.

Instead, please email us at: relay_app@outlook.com

Alternatively, you can use GitHub Security Advisories to report vulnerabilities privately.

Include the following in your report:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (optional)

What to Expect

  • Acknowledgment: We will acknowledge your report within 48 hours
  • Updates: We will keep you informed of our progress
  • Resolution: We aim to resolve critical issues within 7 days
  • Credit: We will credit you in the release notes (unless you prefer anonymity)

Scope

This security policy applies to:

  • The Relay desktop application
  • All code in this repository

Out of Scope

  • Third-party dependencies (please report to their maintainers)
  • Issues in user-provided API keys

Security Best Practices for Users

  1. Keep your API keys secure - Never share your .env file
  2. Review actions before approving - Relay always asks for permission before system changes
  3. Keep Relay updated - Install updates to get the latest security fixes

Thank you for helping keep Relay secure! 🔒

There aren't any published security advisories