Skip to content

Security: beleevens/ThinkOS-Client

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Think, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

How to Report

Use GitHub's private vulnerability reporting

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 7 days
  • Resolution target: Within 30 days for critical issues

Scope

This policy applies to:

  • The Think desktop application
  • The Think Chrome extension
  • The Think backend server

Out of Scope

  • Vulnerabilities in dependencies (report to upstream maintainers)
  • Social engineering attacks
  • Physical attacks

Supported Versions

Version Supported
Latest Yes
< Latest No

We recommend always using the latest version.

There aren’t any published security advisories