Skip to content

Security: siosig/obsidian-nextcloudsync

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

If you discover a security vulnerability, please report it by sending an email to siosig@gmail.com with:

  • Description of the vulnerability
  • Steps to reproduce (if applicable)
  • Affected versions
  • Potential impact

Response Commitment

We take security seriously and will:

  1. Acknowledge your report within 24 hours
  2. Investigate and confirm the vulnerability
  3. Release a patch within 7 days for confirmed critical issues (best effort)
  4. Coordinate disclosure — we will publicly disclose the vulnerability only after a stable release containing the fix is available

Supported Versions

Security updates are provided for the latest stable release. Users are encouraged to upgrade to the latest version.

Version Supported
Latest ✅ Supported
Older ⚠️ Best effort

Public Disclosure

Once a security fix is released in a stable version, we will:

  • Document the vulnerability in the release notes
  • Credit the reporter (unless they prefer anonymity)
  • Provide guidance for affected users to upgrade

There aren't any published security advisories