Artifact Redactor is a local-first text redaction tool and does not ship a hosted service.
Security fixes are applied to the latest released version and the current main branch.
Do not open a public issue first for a suspected security problem.
Send a private report with:
- affected version or commit
- reproduction steps using fake or rotated values
- impact assessment
- any proposed mitigation
Use a GitHub security advisory if the repository has that feature enabled. If not, contact the maintainer privately through the GitHub profile associated with this repository.
If the report involves leaked examples, do not include real secrets, customer data, or absolute local paths in the disclosure.