Please do not open a public GitHub issue for security vulnerabilities.
Instead, report privately through one of:
- GitHub Security Advisories - preferred. Use the Report a vulnerability button on the Security tab of this repository.
- Email - johannes.millan@gmail.com with
[minded security]in the subject line.
Please include:
- A description of the issue and its impact
- Steps to reproduce (or a proof-of-concept)
- Affected platform(s): browser extension, Android, both
- Affected version(s)
- Whether the issue is already publicly known
You should receive an acknowledgement within 7 days. I aim to provide a substantive response (assessment, planned fix, or request for more info) within 30 days, though this is a side-project and timelines may slip.
In-scope:
- The browser extension (Chrome / Firefox)
- The Android app
- Code in this repository
Out-of-scope:
- The marketing site at minded.today (report site issues separately by email)
- Third-party dependencies - please report those upstream
- Social-engineering, physical attacks, denial-of-service
I prefer coordinated disclosure: please give a reasonable window to ship a fix before publishing details. Credit will be given in the release notes unless you prefer to remain anonymous.