Only the latest release of COSINT receives security fixes. Please update to the most recent version (the app updates itself automatically) before reporting an issue.
| Version | Supported |
|---|---|
| Latest release | Yes |
| Older releases | No |
Please do not open a public issue for security problems.
Use GitHub's private vulnerability reporting instead: open the Security tab of this repository and click Report a vulnerability. The report stays private between you and the maintainer until a fix is published.
Please include:
- the COSINT version and operating system (Windows / Linux);
- the component involved (desktop app, signaling server, sync, import/export, update, etc.);
- clear steps to reproduce, and the expected vs. observed behaviour;
- the potential impact (e.g. data exposure between peers, code execution, access-token leak);
- a minimal proof of concept if you have one.
Never attach real investigation data (boards, files, identities, screenshots of real cases). Use synthetic or placeholder data only.
- An acknowledgement of your report as soon as reasonably possible.
- An assessment and, if confirmed, a fix shipped in a new release.
- Credit in the release notes if you wish, once the fix is available.
This is a project maintained on a best-effort basis; response times may vary.
Seule la dernière version publiée de COSINT reçoit des correctifs de sécurité. Pour signaler une vulnérabilité, n'ouvrez pas de ticket public : utilisez le signalement privé de GitHub, via l'onglet Security du dépôt puis Report a vulnerability. Indiquez la version, le système, le composant concerné, les étapes de reproduction et l'impact possible. Ne joignez jamais de données d'enquête réelles : utilisez uniquement des données fictives. Vous recevrez un accusé de réception dès que possible, puis un correctif dans une nouvelle version si le problème est confirmé.