Skip to content

Security: MHJoy99/speedy-bonding

SECURITY.md

Security policy

Scope

Speedy Bonding is a Windows desktop application that creates a loopback SOCKS5 listener and, when Steam Mode is enabled, a temporary elevated TUN adapter.

Reporting a vulnerability

Please do not open a public issue for a vulnerability. Use GitHub's private security advisory flow for MHJoy99/speedy-bonding. Include the affected version, Windows version, reproduction steps, and any relevant logs with secrets removed.

Security expectations

  • The local proxy should remain bound to 127.0.0.1 unless authentication and firewall controls are added.
  • Never put API keys, passwords, private IP inventories, or raw user logs in issues or pull requests.
  • Verify downloaded third-party binaries against their upstream release and checksum before packaging them.
  • Privileged TUN changes must have a clear stop path and must not silently alter unrelated routes.

There aren't any published security advisories