Skip to content

Security: devconsole-android/DevConsole

Security

SECURITY.md

Security policy

DevConsole is for internal/debug builds only. Do not enable it in production variants.

Supported versions

Only the latest 1.x release line receives security fixes. Development snapshots are not supported.

Reporting a vulnerability

Do not file public issues for suspected credential exposure, production inclusion, authentication bypass, or remote code execution. Contact the maintainers through the repository's private security-reporting channel and include a minimal, redacted reproduction. We acknowledge reports within five business days and provide a status update within ten business days.

Handling

We validate reports privately, assign severity, coordinate an embargo when appropriate, release a signed fix, and request a CVE for eligible issues. Production inclusion or credential exposure is treated as critical. Release artifacts must be signed and accompanied by an SBOM/provenance record.

There aren't any published security advisories