Security fixes are provided for the latest published version of DateFrame.
Please do not open a public issue for a vulnerability that could expose private media information, overwrite or delete files unexpectedly, execute unintended commands, or otherwise put a user's library or system at risk.
Report security issues privately through GitHub's Report a vulnerability form in the repository Security tab:
https://github.com/fyulita/dateframe/security/advisories/new
Please include:
- the affected DateFrame version and operating system
- the command or feature involved
- steps to reproduce the issue with non-sensitive sample data when possible
- the potential impact
- any suggested mitigation or fix, if available
Regular bugs that do not expose sensitive information or create a security risk can be reported through the public issue tracker:
https://github.com/fyulita/dateframe/issues
DateFrame processes personal media libraries and its logs can contain full local paths, filenames, metadata values, and effective commands. Before attaching logs or sample files to any report, remove personal information unless it is strictly necessary for a private security report.