-
Notifications
You must be signed in to change notification settings - Fork 0
Security
Use GitHub private vulnerability reporting when available. Include the affected version/platform, impact, realistic attack conditions and minimal reproduction steps.
Never publish credentials, production data, private keys or complete sensitive diagnostics. If the private form is unavailable, open a minimal issue asking to establish private contact without including vulnerability details.
The latest public beta or stable build is the supported security line. Older lines should be upgraded before reporting a problem that may already be fixed.
The renderer is sandboxed and has no direct Node.js, filesystem, SQLite, credential or database-socket access. Sensitive operations cross a validated bridge into Electron's main process. Saved credentials are encrypted locally.
Read-only mode, production confirmations, parameterized mutations, verified update downloads and recovery snapshots reduce mistakes. They do not replace least-privilege database accounts, network controls, reviewed SQL and tested backups.
See the canonical security policy for reporting and supported-version details.
- Connections, SSL and SSH
- SQL Editor
- Tables and Safe Editing
- Backup, Import and Migrations
- Appearance, Language and Sessions
- Updates, Recovery and Restores
- Community, Ideas and Requests
- Security and Privacy
- Privacy
- Security Policy
- Support Policy
- Compatibility
- Troubleshooting
- Frequently Asked Questions
- Roadmap to 1.0
- Version History