Please report security issues privately through the repository's GitHub Security Advisory form.
Include the affected Notch Master version, macOS version, reproduction steps, impact, and any relevant logs. Do not include passwords, API credentials, session tokens, or unrelated personal data.
For vulnerabilities that also affect the upstream Boring Notch project, please notify the upstream maintainers as appropriate. Report third-party dependency vulnerabilities to the corresponding dependency maintainers.