ReProvision Reborn handles security-sensitive workflows, including Apple account authentication, Keychain-stored credentials, provisioning APIs, code signing, URL scheme IPA installation, and background signing.
If GitHub Security Advisories are available for this repository, please report vulnerabilities through the repository's private security advisory flow.
If private advisories are not available, please do not file a public issue for vulnerabilities. Instead, contact the maintainer privately with enough detail to understand and reproduce the issue.
Please include:
- A clear description of the issue and its impact
- Steps to reproduce, if available
- Affected versions, devices, iOS versions, and jailbreak environment, if known
- Any relevant logs or proof-of-concept details, with sensitive account data removed
Response times may vary. The project does not provide a guaranteed response or remediation SLA.
Examples of security issues that are in scope include:
- Credential leakage
- Insecure Keychain access
- Logging of sensitive tokens or account data
- Unsafe handling of IPA URLs
- Signing or provisioning bypasses
- Background daemon privilege or persistence issues
The following are out of scope for security reporting:
- Piracy support
- Modified unofficial builds
- General jailbreak support questions