Skip to content

Security: Bitpainter75/FerrumPix

Security

SECURITY.md

Security Policy

Supported Versions

FerrumPix is currently under active development.

Security fixes are generally provided for the latest available version only. Users are encouraged to update to the newest release before reporting an issue.

Reporting a Vulnerability

If you discover a potential security vulnerability in FerrumPix, please do not open a public GitHub issue.

Instead, please report the vulnerability privately using GitHub's Private Vulnerability Reporting feature, if available.

Please include as much information as possible, such as:

  • The affected FerrumPix version
  • Operating system and architecture
  • A description of the vulnerability
  • Steps required to reproduce the issue
  • Example files or inputs, if relevant
  • The potential security impact
  • Any suggested mitigation or fix

Please avoid publicly disclosing the vulnerability until it has been investigated and, where necessary, a fix has been released.

What Counts as a Security Issue?

Examples include:

  • Arbitrary code execution
  • Unsafe handling of specially crafted image, metadata, project, or sidecar files
  • Path traversal or unintended file access
  • Exposure of credentials, authentication tokens, or private information
  • Vulnerabilities in Immich or Nextcloud communication
  • Security issues involving third-party dependencies
  • Bypasses of security-related restrictions

Normal application bugs, crashes without a security impact, feature requests, and usability problems should be reported through the regular GitHub issue tracker.

Response

Security reports will be reviewed as soon as reasonably possible.

If the issue is confirmed, a fix will be developed before details are publicly disclosed whenever possible.

Thank you for helping keep FerrumPix and its users safe.

There aren't any published security advisories