Skip to content

Security: bigtomcat6/mac-activity

docs/SECURITY.md

Security Policy

MacActivity handles local system metrics, updater metadata, and cleanup actions. Security and privacy-sensitive reports should be handled privately.

Supported Versions

Until MacActivity has a stable public release line, security fixes target the current main branch and the latest published release or prerelease artifact.

Older prerelease artifacts are supported only when the issue still reproduces on current main or the latest available artifact.

Reporting a Vulnerability

Do not open a public issue with exploit details, private data, crash logs that contain sensitive paths, proof-of-concept code, signing material, or private Sparkle keys.

Preferred reporting path:

  1. Use GitHub private vulnerability reporting if it is enabled for this repository.
  2. If private vulnerability reporting is not enabled, open a minimal public issue asking for a private maintainer contact. Do not include technical details in that issue.

Include:

  • Affected version, commit, or artifact.
  • macOS version and hardware architecture.
  • Clear reproduction steps.
  • Expected and actual security impact.
  • Whether the issue involves cleanup deletion scope, process termination, launch-at-login behavior, local file access, system metrics, app signing, Sparkle updater metadata, or release artifacts.

Disclosure

Maintainers should acknowledge reports before public discussion, reproduce the issue, decide severity, and prepare a fix or mitigation before publishing detailed vulnerability information.

There aren't any published security advisories