Skip to content

Security: rilvert/zwimki

Security

SECURITY.md

Security Policy

Supported Versions

This project is under active development. Security fixes are applied to the latest main branch.

Reporting a Vulnerability

Please do not open public issues for sensitive vulnerabilities.

Send a private report with:

  • Description of the issue
  • Reproduction steps
  • Affected commit/version
  • Potential impact

Until a dedicated security mailbox exists, open a private channel with the maintainers and avoid public disclosure until a fix is available.

Operational Guidance

  • Default UI bind is localhost (127.0.0.1)
  • If binding to a network interface, set ZWIMKI_ACCESS_TOKEN
  • Treat .zwimki/ data as local state and do not commit it

There aren't any published security advisories