If you find a security issue in Coax — especially anything involving the encrypted-secrets store, the IPC surface between renderer and main process, or request execution — please do not open a public issue.
Instead, either:
- use GitHub's private vulnerability reporting, or
- email support@melodic.dev with the details.
Include steps to reproduce and what an attacker could gain. You'll get an acknowledgment as soon as possible, and a fix will be released before any public disclosure. Thanks for reporting responsibly.
Only the latest release receives security fixes. Coax auto-updates, so staying current is the default.