Skip to content

Security: weskcode/rhoids

SECURITY.md

Security Policy

Reporting a Vulnerability

Please report suspected security or privacy issues privately to wesleyk@duck.com. Include the affected version, reproduction steps, impact, and any supporting logs or screenshots that do not expose unrelated personal data.

Do not open a public issue for an unpatched vulnerability. Please allow reasonable time to investigate and prepare a fix before public disclosure.

Please do not include timer history, selected-app details, Apple account information, signing material, or other unrelated personal data in a report.

Supported Versions

Security fixes are made against the current development branch and the current App Store release when applicable. Older releases may require an update to receive a fix.

Scope

Useful reports include unintended disclosure of local data, unsafe handling of App Group state, bypasses in Focus Lock behavior, exposed credentials, insecure external links, or vulnerabilities in app, widget, Watch, intent, and Screen Time extension boundaries.

App Store review decisions, feature requests, and expected Apple platform permission behavior are not security vulnerabilities, but ordinary defects can still be reported through the project’s normal feedback channel.

There aren't any published security advisories