Security Policy

June 18, 2026 · View on GitHub

Supported versions

WinMD is a desktop application; security fixes are made against the latest release. Please make sure you are on the most recent version before reporting an issue.

VersionSupported
Latest release
Older releases

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, use GitHub's private vulnerability reporting:

  1. Go to the repository's Security tab.
  2. Click Report a vulnerability (Private vulnerability reporting).
  3. Describe the issue, steps to reproduce, and impact.

If private reporting is unavailable, contact the maintainer privately through GitHub (@toevi) and ask for a secure channel before sharing details.

What to expect

  • Acknowledgement of your report as soon as possible.
  • An assessment and, if confirmed, a fix in a subsequent release.
  • Credit for the report if you wish.

Thank you for helping keep WinMD and its users safe.