This policy covers every JAD Apps repository that does not carry its own.
Do not open a public issue for a security vulnerability.
Report privately through either channel:
- GitHub Security Advisories — the repository's Security → Report a vulnerability tab. This is the preferred channel.
- Email —
johndonnelly383@gmail.com, with[security]and the product name in the subject line.
Please include:
- the product and version (Help → About in the desktop apps);
- your Windows version and build;
- a description of the issue and its security impact;
- reproduction steps or a proof of concept;
- any suggested remediation.
- Acknowledgement within 3 business days.
- Triage and severity assessment within 7 business days.
- Fix and coordinated disclosure timeline communicated after triage. We aim to ship a fix within 90 days and will keep you updated.
- Credit in the release notes and advisory, unless you ask to remain anonymous.
In scope: the applications published from this organisation and the release artifacts on their Releases pages.
Out of scope: vulnerabilities in Windows, the Windows App SDK, .NET or other third-party dependencies — report those upstream. We will still act on a report showing that a JAD Apps product uses such a component unsafely.
Release binaries are currently unsigned, so Windows SmartScreen warns on first run. This is a known gap, not a finding — code-signing certificates are in progress. Verify downloads came from the official Releases page.