Please do not publish security vulnerabilities, private data exposures, or potential data-loss issues in a public GitHub issue. Report them privately to the repository maintainers with:
- A clear description of the issue and its potential impact.
- Steps to reproduce, a proof of concept, or relevant code locations.
- Affected version, operating system, and package type.
- Any suggested mitigation, when available.
Do not include real household records, receipt images, access tokens, passwords, database files, or backup archives in a report.
Security fixes are applied to the current development branch and the latest released version when a release exists.
Ivenn stores inventory information and attachments locally. Contributors must preserve this expectation: do not add telemetry, cloud uploads, or third-party data transfers without explicit user consent, clear documentation, and maintainer approval.