|
|
The ZFordDev ecosystem values stability, safety, and long‑term maintainability.
We take security seriously and appreciate responsible disclosure of any vulnerabilities.
This document explains how to report security issues and what to expect during the process.
Security updates are provided for:
- Current stable releases
- Active development branches
- Classic versions, where applicable
Older or archived versions may not receive fixes.
If you discover a security issue, please report it responsibly.
- Open a private GitHub security advisory (preferred)
- Or contact the project maintainer directly through GitHub
Please do not open a public issue for security vulnerabilities.
- Description of the issue
- Steps to reproduce
- Impact or potential risk
- Affected versions
- Any relevant logs or screenshots
Clear reports help us respond quickly.
When a report is received:
- The maintainer will acknowledge the report
- The issue will be investigated
- A fix or mitigation will be prepared
- A patched release will be published
- A security advisory will be issued (if applicable)
We aim to handle all reports respectfully and promptly.
This policy applies to:
- All ZFordDev repositories
- All official releases
- All ecosystem tools and modules
It does not apply to:
- Third‑party dependencies
- Forks or modified builds
- Unofficial distributions
SnapDock is a desktop application built on Electron.
When reporting security issues, please consider:
- Electron/Chromium vulnerabilities should be reported upstream when appropriate
- SnapDock does not execute remote code or load remote content
- All Markdown rendering is local and sandboxed
- The in‑app updater is disabled in some versions (store builds, certain Linux packages, and some pre‑releases)
- SnapDock does not collect telemetry or send user data anywhere
If a vulnerability involves file handling, workspace logic, or the update system, please include reproduction steps for both Windows and Linux if possible.
Responsible disclosure helps keep the entire ZFordDev ecosystem safe.
We appreciate your effort and your commitment to improving the project.