Skip to content

Security: AstraeLabs/VibraVid

Security

.github/SECURITY.md

Security Policy

Supported Versions

Only the latest released version of VibraVid is supported with security fixes. The app itself checks for and prompts you to update to the latest release — please update before reporting an issue to confirm it still reproduces there.

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Instead, use GitHub's private vulnerability reporting for this repository:

  1. Go to the Security tab.
  2. Click "Report a vulnerability".
  3. Describe the issue: affected component/version, steps to reproduce, and potential impact.

This opens a private advisory visible only to you and the maintainers, so the issue can be discussed and fixed before it's public.

If you'd rather not use GitHub for the initial report, you can also reach the maintainers on the project's Discord server and ask for a private channel — please still avoid posting exploit details in a public channel there.

What to expect

We'll acknowledge new reports as soon as we can and keep you updated as we work on a fix. Once a fix is released, we'll credit the reporter (unless you'd prefer to stay anonymous) in the release notes or a GitHub security advisory.

There aren't any published security advisories