Skip to content

Security: hideouts-io/MacScope

SECURITY.md

Security policy

Security tools have to hold themselves to a higher standard. If you find a vulnerability in a hideouts project or on hideouts.io, please report it privately first.

How to report

Use private vulnerability reporting on the affected repository: open its Security tab and choose Report a vulnerability. Only maintainers can see these reports.

Please don't open a public issue, discussion, or pull request for a vulnerability. For problems with the hideouts.io website itself, report through the iOS Developer Toolkit repository and say it concerns the website.

What to include

  • The project and the version, release tag, or commit.
  • Your macOS or iOS version and build.
  • Steps to reproduce, the expected result, and the actual result.
  • The impact as you understand it, limited to what you observed.

Never include credentials, private keys, personal data, device backups, or unrestricted forensic evidence. Sanitize logs and screenshots first.

What to expect

  • An acknowledgement once the report has been read, and an honest assessment of whether it's in scope.
  • Coordination on a fix and a disclosure date before anything is made public.
  • Credit in the release notes if you'd like it.

Supported versions

Fixes go into the latest release and the default branch. Older releases aren't patched separately.

Safe harbor

Good-faith research on your own devices and your own copies of these projects is welcome. Don't test against systems or devices you aren't authorized to examine, access other people's data, or degrade anyone's service.

More detail: hideouts.io/security.

There aren't any published security advisories