This policy covers all AetherAssembly projects. We take security reports seriously and will act on them as quickly as we can. This page explains how to reach us, what to expect from us, and how we handle things from receipt through to fix and disclosure.
Please do not disclose vulnerabilities in public issues, pull requests, or comment threads. Use GitHub private vulnerability reporting on the relevant repository if it is enabled, or contact us directly through one of the following:
To help us triage quickly, include: a clear description of the issue, steps to reproduce it, your assessment of the impact, and any suggested fix or workaround if you have one. We don't require a CVE or a formal writeup — plain language is fine.
We aim to acknowledge every report within 7 days. From there, here is roughly what the process looks like:
Security patches are applied to the current release and the two most recent releases of each project. Older versions are not actively patched. If you're on an older version, updating to the latest release is always the safest option.
We're most interested in issues that could realistically affect users: things like data exposure, privilege escalation, unsafe handling of user input, insecure IPC or storage patterns, or supply chain risks in our dependencies. All three projects are in scope: Attyre, Before It's Gone, and MindTab.
The following are generally not treated as security issues: theoretical vulnerabilities without a working proof of concept, issues that require physical access to an already-compromised device, social engineering, self-XSS, missing security headers on pages that don't handle sensitive data, and reports generated by automated scanners without manual verification. General bugs and feature requests belong in the normal issue tracker on GitHub or the GitLab mirror.