Skip to content

Security: rsitech-ai/SnapAction

SECURITY.md

Security policy

Supported versions

Security fixes are provided for the latest published release and the current main branch. Older releases may not receive fixes.

Private reporting

Do not disclose suspected vulnerabilities, exploit details, credentials, OCR content, clipboard content, screenshots, or workstation data in public issues or pull requests.

Use GitHub's private vulnerability reporting for this repository when available, or email info@rsitech.ai with the subject SnapAction security report. This address is the public and confidential project contact managed by RSI Tech.

Include a concise impact description, affected revision/version, safe reproduction steps, and any suggested remediation. Remove unrelated private data. RSI Tech will acknowledge a valid report as capacity permits, coordinate remediation and disclosure, and credit reporters who request attribution. No fixed response-time or bounty commitment is offered.

The formal Codex Security scan was skipped by explicit owner direction for the initial publication. That omission is disclosed as an accepted residual risk and is not represented as a completed security review.

There aren't any published security advisories