Security fixes are evaluated for the latest stable SC220 Live release published in this repository.
| Version | Supported |
|---|---|
| Latest stable release | Yes |
| Older releases | Best effort |
| Repackaged or third-party builds | No |
Please do not disclose security vulnerabilities, exploit details, credentials, activation data, or sensitive logs in a public issue.
Preferred reporting path:
- Open the repository's Security tab.
- Use Report a vulnerability or the private security advisory flow when available.
- Include the affected version, impact, reproduction steps, and a minimal proof of concept.
- Remove unrelated personal information, license data, and credentials.
If private vulnerability reporting is not available, open a public issue titled Security contact request without technical details. A private reporting channel can then be arranged.
Examples include:
- Installer tampering or release-integrity issues.
- Unsafe handling of local files, paths, or configuration data.
- Credential, activation, or private-data exposure.
- Privilege escalation or arbitrary code execution.
- Insecure update or download behavior.
- Vulnerabilities in the public landing page that could affect visitors.
- Windows SmartScreen showing an unknown-publisher warning by itself.
- A checksum mismatch for a file downloaded from an unofficial mirror.
- General audio quality, latency, routing, or device-compatibility problems.
- Requests for proprietary source code or signing material.
Only trust installers published under this repository's GitHub Releases. Verify the SHA-256 checksum before installation and avoid repackaged binaries from third-party download sites.
After a report is received, the maintainer will attempt to:
- Confirm receipt.
- Reproduce and assess severity.
- Prepare a fix or mitigation when applicable.
- Publish an updated release and advisory when disclosure is appropriate.
Timelines depend on severity, reproducibility, and affected dependencies. Coordinated disclosure is appreciated.