Skip to content

Security: pour-soi/PourInput

Security

SECURITY.md

Security Policy

Supported Versions

The latest public release receives security fixes. Older development builds and local forks are not guaranteed to receive backported fixes.

Version Supported
v0.1.x Yes

Reporting a Vulnerability

Please report security issues privately when possible.

Preferred options:

  1. Use GitHub private vulnerability reporting if it is enabled for this repository.
  2. If private reporting is not available, open a minimal public issue asking for a private contact path. Do not include exploit details, private logs, credentials, or sensitive device data in the public issue.

Scope

Security reports may include:

  • Unsafe update, download, or packaging behavior.
  • Sensitive log disclosure.
  • Unsafe file handling.
  • Input simulation behavior that can be triggered unexpectedly.
  • Dependency vulnerabilities that affect packaged releases.

General feature requests, device support requests, and normal remapping bugs should use the regular issue templates.

There aren't any published security advisories