MacActivity handles local system metrics, updater metadata, and cleanup actions. Security and privacy-sensitive reports should be handled privately.
Until MacActivity has a stable public release line, security fixes target the
current main branch and the latest published release or prerelease artifact.
Older prerelease artifacts are supported only when the issue still reproduces on
current main or the latest available artifact.
Do not open a public issue with exploit details, private data, crash logs that contain sensitive paths, proof-of-concept code, signing material, or private Sparkle keys.
Preferred reporting path:
- Use GitHub private vulnerability reporting if it is enabled for this repository.
- If private vulnerability reporting is not enabled, open a minimal public issue asking for a private maintainer contact. Do not include technical details in that issue.
Include:
- Affected version, commit, or artifact.
- macOS version and hardware architecture.
- Clear reproduction steps.
- Expected and actual security impact.
- Whether the issue involves cleanup deletion scope, process termination, launch-at-login behavior, local file access, system metrics, app signing, Sparkle updater metadata, or release artifacts.
Maintainers should acknowledge reports before public discussion, reproduce the issue, decide severity, and prepare a fix or mitigation before publishing detailed vulnerability information.