Skip to content

Security: opencorex-org/macsweep

Security

SECURITY.md

Security Policy & Vulnerability Disclosure

Organization: OpenCorex
Project: MacSweep (opencorex-org/macsweep)


1. Supported Versions

Security updates and safety patches are actively applied to the following versions of MacSweep:

Version Supported
1.x.x Yes
0.1.x (Beta MVP) Yes
< 0.1.0 No

Security Philosophy

The OpenCorex maintainers take security and user data safety extremely seriously. If you discover a security vulnerability, path traversal flaw, privilege escalation risk, or potential data loss scenario in MacSweep:

Please DO NOT open a public GitHub issue.

Instead, report vulnerabilities privately through one of the following channels:

What to Include in Your Report

  • A detailed description of the vulnerability.
  • Steps to reproduce the issue cleanly.
  • Potential security or safety impact (e.g., unexpected path deletion, symlink escape).
  • Proof-of-concept script or test case if available.

3. Response & Resolution Process

  1. Acknowledgement: We will acknowledge receipt of your security report within 24 hours.
  2. Assessment: The OpenCorex security team will investigate and validate the report within 72 hours.
  3. Patch & Release: A security patch will be developed, tested, and released as a hotfix version.
  4. Public Disclosure: A coordinated public security advisory will be published detailing the fix.

Thank you for helping keep MacSweep safe for the open-source community!

There aren't any published security advisories