The latest GitHub Release receives security fixes.
| Version | Supported |
|---|---|
| 0.1.x | Yes |
| Older | No |
Use GitHub private vulnerability reporting. Do not open a public issue for a vulnerability that could expose roster data, inject active content into reports, escape an output path, or bypass a hard constraint.
Include a minimal synthetic scenario, affected version, platform, command, observed result, and expected result. Do not include real names or sensitive attributes.
RosterFair makes no network requests and has no telemetry. Inputs and outputs remain local. HTML reports embed the full assignment data so they work offline; anyone who receives the report can inspect that data.
The release preflight scans common secret formats, but it cannot prove that arbitrary names, notes, or custom attributes are safe to publish.