Skip to content

Security: openza/reader

SECURITY.md

Security Policy

Openza Reader renders Markdown that may come from untrusted sources. Security reports are welcome and should be handled privately before public disclosure.

Supported Versions

Openza Reader is publicly available through the Microsoft Store. Security fixes are made on the default branch and shipped in the next Store update.

Version Supported
1.1.x Yes, after the Store update is published
1.0.x Yes

Reporting A Vulnerability

Please do not open a public issue for a suspected vulnerability.

Use Report a vulnerability on the repository's Security page to open a private report. If private vulnerability reporting is unavailable, contact the maintainers through the Openza project owner account and include:

  • A clear description of the issue
  • Steps to reproduce
  • A minimal Markdown sample or file when possible
  • Expected impact
  • Your preferred credit/disclosure details

Security Model

See docs/security.md for the app security model and V1 constraints.

There aren't any published security advisories