Skip to content

Security: Yuriyagn/controlled-tagger

Security

SECURITY.md

Security Policy

Supported versions

Only the latest published release receives security fixes.

Reporting a vulnerability

Please use GitHub's private vulnerability reporting feature for this repository when available. If it is unavailable, open a minimal issue asking the maintainer for a private contact method.

Do not include API keys, access tokens, private note contents, or unredacted Vault paths in a public issue.

Data handling summary

  • API keys are stored by Obsidian in the plugin's plaintext data.json.
  • Note content is sent only to the API endpoint configured by the user and only after a user-triggered suggestion request.
  • The plugin has no telemetry, analytics, advertising, or author-operated backend.

There aren't any published security advisories