Skip to content

Security: Radek-B3/browser3

Security

SECURITY.md

Security policy

Supported versions

Only the newest Browser3 release listed on the official release page is supported.

Reporting a vulnerability

Do not open a public issue for a suspected vulnerability. Email radekcisar77@gmail.com with the subject Browser3 security report and include:

  • the affected Browser3 version and archive SHA-256;
  • operating-system and reproduction details;
  • the expected and observed security impact;
  • a minimal proof of concept, if it can be shared safely.

Do not include credentials, personal data, or third-party secrets. Encrypt sensitive attachments to the public release key when practical.

The maintainer aims to acknowledge a complete report within 7 days and provide an initial assessment within 14 days. These are targets, not a support-level agreement. There is currently no bug-bounty program.

Responsible testing

Test only systems, accounts, and data you own or have explicit permission to assess. Do not exploit a vulnerability beyond what is needed to demonstrate impact, and allow reasonable time for remediation before public disclosure.

There aren't any published security advisories