Skip to content

Security: MelodicDevelopment/coax

SECURITY.md

Security Policy

Reporting a vulnerability

If you find a security issue in Coax — especially anything involving the encrypted-secrets store, the IPC surface between renderer and main process, or request execution — please do not open a public issue.

Instead, either:

Include steps to reproduce and what an attacker could gain. You'll get an acknowledgment as soon as possible, and a fix will be released before any public disclosure. Thanks for reporting responsibly.

Supported versions

Only the latest release receives security fixes. Coax auto-updates, so staying current is the default.

There aren't any published security advisories