Skip to content

Security: JAD-Apps/jad-runner

SECURITY.md

Security Policy

This policy covers every JAD Apps repository that does not carry its own.

Reporting a vulnerability

Do not open a public issue for a security vulnerability.

Report privately through either channel:

  1. GitHub Security Advisories — the repository's Security → Report a vulnerability tab. This is the preferred channel.
  2. Emailjohndonnelly383@gmail.com, with [security] and the product name in the subject line.

Please include:

  • the product and version (Help → About in the desktop apps);
  • your Windows version and build;
  • a description of the issue and its security impact;
  • reproduction steps or a proof of concept;
  • any suggested remediation.

What to expect

  • Acknowledgement within 3 business days.
  • Triage and severity assessment within 7 business days.
  • Fix and coordinated disclosure timeline communicated after triage. We aim to ship a fix within 90 days and will keep you updated.
  • Credit in the release notes and advisory, unless you ask to remain anonymous.

Scope

In scope: the applications published from this organisation and the release artifacts on their Releases pages.

Out of scope: vulnerabilities in Windows, the Windows App SDK, .NET or other third-party dependencies — report those upstream. We will still act on a report showing that a JAD Apps product uses such a component unsafely.

A note on unsigned builds

Release binaries are currently unsigned, so Windows SmartScreen warns on first run. This is a known gap, not a finding — code-signing certificates are in progress. Verify downloads came from the official Releases page.

There aren't any published security advisories