Skip to content

Security: abdalhalimalzohbi/StashPad

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest minor release receives security fixes.

Version Supported
0.1.x
< 0.1.0

Reporting a Vulnerability

Please do not file public GitHub issues for security problems.

Instead, report privately using one of:

  • GitHub Security Advisories — Open a private advisory on this repository.
  • Email — azohbi123@gmail.com with subject [StashPad security].

Include:

  1. A description of the issue and the impact.
  2. Steps to reproduce, or a proof-of-concept.
  3. Affected version(s).
  4. Suggested mitigation if you have one.

We will acknowledge receipt within 72 hours and aim to ship a fix within 14 days for high-severity issues. You will be credited in the release notes unless you ask otherwise.

Out of scope

  • Issues affecting unsupported versions.
  • Vulnerabilities requiring elevated local access (the extension runs with the user's own VS Code permissions by design).
  • Reports generated solely by automated scanners with no working exploit.

There aren't any published security advisories