Skip to content

Security: kynasln/timming

Security

SECURITY.md

Security Policy

Supported versions

Version Supported
4.x Yes
< 4.0 Best-effort only

Reporting a vulnerability

Please do not open a public issue for security-sensitive reports.

Prefer one of:

  1. GitHub Private vulnerability reporting on this repository (Security tab), if enabled
  2. Contact the maintainer via GitHub: @kynasln

Include:

  • Description and impact
  • Reproduction steps / PoC (non-destructive)
  • Affected version / commit
  • Suggested fix if you have one

We will acknowledge reports when possible and work on a fix or mitigation. Please allow reasonable time before any public disclosure.

Scope notes

This app requires camera permission and stores lap data / optional photos on-device. Reports about unsafe handling of local files, export paths, or dependency CVEs are in scope. Physical “adversarial lighting” that fools the detector is expected hobby-grade behavior, not a security vulnerability.

There aren't any published security advisories