Skip to content

Security: legal-machines/react-cpp-desktop

SECURITY.md

Security policy

Supported version

Security fixes are applied to the latest commit on main. Generated applications are independent repositories and should carry their own update and disclosure policy.

Report a vulnerability

Please do not open a public issue for a suspected vulnerability. Use GitHub private vulnerability reporting and include affected platforms, reproduction steps, impact, and any proposed mitigation.

We aim to acknowledge a complete report within seven days. Timelines for a fix and disclosure depend on severity and upstream dependencies.

Security scope

The native bridge is privileged. Applications generated from this repository must validate all native inputs, keep capabilities narrow, and configure code signing, notarization, update delivery, and secret handling for their own threat model.

There aren't any published security advisories