Open Diff is in an early stage. Security fixes are provided for the latest released version unless otherwise noted in a release announcement.
Please do not create a public issue for a security vulnerability.
Report vulnerabilities by opening a private security advisory on GitHub when available:
https://github.com/kygo8/open-diff/security/advisories/new
If private advisories are unavailable, contact the maintainers through the repository owner profile and include:
- Affected version or commit
- Operating system
- Steps to reproduce
- Potential impact
- Any proof-of-concept files or screenshots that are safe to share privately
The maintainers will acknowledge valid reports, investigate the issue, and coordinate disclosure through a release note or advisory when appropriate.