Skip to content

Security: zack-dev-cm/artifact-redactor

Security

SECURITY.md

Security Policy

Artifact Redactor is a local-first text redaction tool and does not ship a hosted service.

Supported versions

Security fixes are applied to the latest released version and the current main branch.

Reporting a vulnerability

Do not open a public issue first for a suspected security problem.

Send a private report with:

  • affected version or commit
  • reproduction steps using fake or rotated values
  • impact assessment
  • any proposed mitigation

Use a GitHub security advisory if the repository has that feature enabled. If not, contact the maintainer privately through the GitHub profile associated with this repository.

If the report involves leaked examples, do not include real secrets, customer data, or absolute local paths in the disclosure.

There aren't any published security advisories