Skip to content

Security: CasualDeveloper/AuthCompanion

Security

SECURITY.md

Security policy

Security fixes target the latest release and main.

Do not publish authentication bypasses, unsafe privilege-boundary behavior, unintended command execution, or rollback failures in a public issue. Use GitHub private vulnerability reporting when available. Otherwise, open a minimal issue requesting a private channel without including exploit details.

Include the affected AuthCompanion and component versions, macOS version and architecture, the smallest safe reproduction, and the expected and observed result. Remove usernames, local paths, authentication prompts, credentials, signing material, and other private data.

The project never needs a password, token, signing identity, private key, or remote access to investigate a report.

There aren't any published security advisories