Only the latest minor release receives security fixes.
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
| < 0.1.0 | ❌ |
Please do not file public GitHub issues for security problems.
Instead, report privately using one of:
- GitHub Security Advisories — Open a private advisory on this repository.
- Email —
azohbi123@gmail.comwith subject[StashPad security].
Include:
- A description of the issue and the impact.
- Steps to reproduce, or a proof-of-concept.
- Affected version(s).
- Suggested mitigation if you have one.
We will acknowledge receipt within 72 hours and aim to ship a fix within 14 days for high-severity issues. You will be credited in the release notes unless you ask otherwise.
- Issues affecting unsupported versions.
- Vulnerabilities requiring elevated local access (the extension runs with the user's own VS Code permissions by design).
- Reports generated solely by automated scanners with no working exploit.