Data Organizer handles password-protected, encrypted user data, so security reports are taken seriously and are always welcome.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, report them privately through GitHub's built-in reporting:
- Open the Security tab of this repository.
- Click Report a vulnerability.
- Fill in the advisory form with the details listed below.
This opens a private channel visible only to the maintainer. The report stays confidential until a fix is available and an advisory is published.
To help reproduce and assess the issue, please provide as much as you can:
- A description of the vulnerability and its potential impact.
- Steps to reproduce, or a proof of concept.
- The affected version, commit, or build.
- Your operating system and .NET runtime version.
- Any suggested mitigation, if you have one.
- Reports are acknowledged within 7 days.
- You will be kept informed as the issue is investigated and resolved.
- With your consent, your contribution will be credited in the published advisory.
Security fixes are applied to the latest release. Older versions are not maintained — please update to the most recent version before reporting an issue.