Only the latest release of Castla receives security updates. Please make sure you are running the most recent version from the Releases page before reporting an issue.
| Version | Supported |
|---|---|
| Latest release | ✅ |
| Older releases | ❌ |
Please do not report security vulnerabilities through public GitHub issues.
Instead, report them privately using GitHub's private vulnerability reporting. This keeps the details confidential until a fix is available.
When reporting, please include as much of the following as you can:
- The type of issue (e.g. privilege escalation, unauthorized data access, insecure network exposure of the local stream)
- Affected version(s) and device / Android version
- Step-by-step instructions to reproduce
- Proof-of-concept or exploit code, if available
- The potential impact
- We aim to acknowledge your report within 72 hours.
- We will keep you informed as we investigate and work on a fix.
- Once a fix is released, we are happy to credit you in the release notes unless you prefer to remain anonymous.
Thank you for helping keep Castla and its users safe.