Skip to content

Security: Skylab008/StackRunway

SECURITY.md

Security policy

Supported version

The latest version on the main branch is supported.

Reporting a vulnerability

Please do not publish exploit details in a public issue.

Use GitHub's private vulnerability reporting option for this repository when it is available. If it is not available, open a minimal issue stating that you need to report a security concern privately, without including sensitive details or a proof of concept.

Reports should identify the affected behaviour, the potential impact, reproducible conditions and any suggested remediation. Acknowledgement should be expected within seven days.

Security model

StackRunway has no server, account system, bank connection, analytics or runtime dependency. Expense data is stored in the user's browser and can be exported to a local JSON file. Users are responsible for protecting exported backups and devices on which browser data is stored.

There aren't any published security advisories