Skip to content

Security: ChanTso/rednote-archivist

SECURITY.md

Security Policy

Reporting a vulnerability

Please use GitHub's Security → Report a vulnerability flow instead of opening a public issue. Include the affected version, reproduction steps, impact, and any suggested mitigation.

Do not include live credentials, cookies, browser-profile files, private collection URLs, or personal data in a report. Use synthetic examples and redact sensitive query values.

Scope

Security issues include credential exposure, unsafe path handling, unexpected network disclosure, bypass of access controls, and leakage of archived user data. Platform login or risk-control bypasses are explicitly out of scope and will not be implemented.

There aren't any published security advisories