Skip to content

Security: nextbrowser-oss/nextbrowser-app

SECURITY.md

Security Policy

Supported scope

Security fixes target the repository's default branch. This repository contains the Nextbrowser desktop application, Electron integration, packaging configuration, and community documentation. The separately distributed browser runtime is outside this repository's scope.

Report privately

Do not disclose a suspected vulnerability in a public issue, discussion, pull request, or comment.

This repository is public and private vulnerability reporting is enabled. Submit reports at:

https://github.com/nextbrowser-oss/nextbrowser-app/security/advisories/new

A useful report includes:

  • the affected file, route, or component;
  • impact and required preconditions;
  • reproducible steps or a minimal proof of concept;
  • suggested mitigations, if known;
  • whether the issue has been disclosed elsewhere.

If the issue belongs to an upstream Nextbrowser or Clawbrowser project, use that project's published private reporting process.

Responsible testing

Only test systems and accounts you are authorized to test. Avoid privacy violations, service disruption, destructive actions, and access to data that is not yours. Give maintainers reasonable time to investigate and coordinate disclosure before publishing details.

There aren't any published security advisories