Skip to content

Security: k0nrd/COSINT

SECURITY.md

Security Policy

Supported versions

Only the latest release of COSINT receives security fixes. Please update to the most recent version (the app updates itself automatically) before reporting an issue.

Version Supported
Latest release Yes
Older releases No

Reporting a vulnerability

Please do not open a public issue for security problems.

Use GitHub's private vulnerability reporting instead: open the Security tab of this repository and click Report a vulnerability. The report stays private between you and the maintainer until a fix is published.

Please include:

  • the COSINT version and operating system (Windows / Linux);
  • the component involved (desktop app, signaling server, sync, import/export, update, etc.);
  • clear steps to reproduce, and the expected vs. observed behaviour;
  • the potential impact (e.g. data exposure between peers, code execution, access-token leak);
  • a minimal proof of concept if you have one.

Never attach real investigation data (boards, files, identities, screenshots of real cases). Use synthetic or placeholder data only.

What to expect

  • An acknowledgement of your report as soon as reasonably possible.
  • An assessment and, if confirmed, a fix shipped in a new release.
  • Credit in the release notes if you wish, once the fix is available.

This is a project maintained on a best-effort basis; response times may vary.


Politique de sécurité (français)

Seule la dernière version publiée de COSINT reçoit des correctifs de sécurité. Pour signaler une vulnérabilité, n'ouvrez pas de ticket public : utilisez le signalement privé de GitHub, via l'onglet Security du dépôt puis Report a vulnerability. Indiquez la version, le système, le composant concerné, les étapes de reproduction et l'impact possible. Ne joignez jamais de données d'enquête réelles : utilisez uniquement des données fictives. Vous recevrez un accusé de réception dès que possible, puis un correctif dans une nouvelle version si le problème est confirmé.

There aren't any published security advisories