Skip to content

Security: rmellis/open-publisher

Security

SECURITY.md

Security Policy

Supported Versions

OpenPublisher operates on a continuous, rolling release model. The application automatically and silently pulls the latest updates directly from the host the moment it is opened. Because all legacy versions are completely compatible with one another and upgrade automatically to the newest build, we only provide security patches for the latest active release.

Version Supported
Latest (Rolling)
Older Versions

(Note: Whether the project is currently in the 4.0.x or 4.21.x, The app ensures you are always on the fully supported track simply by launching the app). (the major releases may require manual udpates after large client side changes)

Reporting a Vulnerability

We take the security of OpenPublisher and its users very seriously. Because OpenPublisher is maintained by a small team and functions without ads or subscriptions, we ask that you report any security vulnerabilities directly and privately before opening any public GitHub issues.

How to Report: Please email your findings directly to security@openpublisher.app or contact us via our GitHub inbox.

What to Include:

  • A clear description of the vulnerability and its potential impact.
  • Detailed steps to reproduce the issue.
  • Your operating system (Windows, macOS, or Linux) or if you are using the web version.

What to Expect:

  • Acknowledgment: We will acknowledge receipt of your vulnerability report as soon as possible.
  • Assessment & Fix: We will assess the severity and begin working on a patch. Because OpenPublisher pushes updates instantly to all users, any implemented security patch will be automatically deployed upon the user's next launch.
  • Disclosure: Once the patch is live and we confirm the vulnerability is resolved across the user base, we will coordinate with you on any public disclosure.

For detailed information on the software's architecture and supported features, please refer to the documentation.pdf guide.

There aren't any published security advisories