Skip to content

Security: SoulRune/ReProvision-Reborn_Rootless

Security

SECURITY.md

Security Policy

ReProvision Reborn handles security-sensitive workflows, including Apple account authentication, Keychain-stored credentials, provisioning APIs, code signing, URL scheme IPA installation, and background signing.

Reporting a Vulnerability

If GitHub Security Advisories are available for this repository, please report vulnerabilities through the repository's private security advisory flow.

If private advisories are not available, please do not file a public issue for vulnerabilities. Instead, contact the maintainer privately with enough detail to understand and reproduce the issue.

Please include:

  • A clear description of the issue and its impact
  • Steps to reproduce, if available
  • Affected versions, devices, iOS versions, and jailbreak environment, if known
  • Any relevant logs or proof-of-concept details, with sensitive account data removed

Response times may vary. The project does not provide a guaranteed response or remediation SLA.

In Scope

Examples of security issues that are in scope include:

  • Credential leakage
  • Insecure Keychain access
  • Logging of sensitive tokens or account data
  • Unsafe handling of IPA URLs
  • Signing or provisioning bypasses
  • Background daemon privilege or persistence issues

Out of Scope

The following are out of scope for security reporting:

  • Piracy support
  • Modified unofficial builds
  • General jailbreak support questions

There aren't any published security advisories