| Version | Supported |
|---|---|
| Latest 1.x release | Yes |
| Unreleased development code | Best effort |
| Noctalia v5 ports | Not yet supported |
Please use GitHub's Report a vulnerability flow in the repository Security tab. It creates a private security advisory visible only to the reporter and maintainers.
Do not include exploit details, private data, or sensitive logs in a public issue or discussion. If private vulnerability reporting is unavailable, contact the maintainer through the address published on their GitHub profile and mention only that you need a private security channel.
Include the affected version, Noctalia version, environment, impact, and the smallest safe reproduction description. You should receive an acknowledgment within seven days. Timelines for a fix or disclosure depend on severity and maintainer availability.