Do not open a public issue. Open a private vulnerability report on GitHub instead. The report stays private until a fix is released.
Include:
- A description of the vulnerability
- Steps to reproduce
- Affected versions
- Impact (what can an attacker do?)
- Acknowledgment within 48 hours
- Assessment and plan within 7 days
- Fix released as soon as practical, depending on severity
In scope:
- The Runway desktop application
- The built-in providers (credential handling, API calls)
- The local HTTP API
- Build and release infrastructure
Out of scope:
- Third-party provider APIs (report to the provider)
- Social engineering
- Denial of service
Only the latest release receives security updates.