FerrumPix is currently under active development.
Security fixes are generally provided for the latest available version only. Users are encouraged to update to the newest release before reporting an issue.
If you discover a potential security vulnerability in FerrumPix, please do not open a public GitHub issue.
Instead, please report the vulnerability privately using GitHub's Private Vulnerability Reporting feature, if available.
Please include as much information as possible, such as:
- The affected FerrumPix version
- Operating system and architecture
- A description of the vulnerability
- Steps required to reproduce the issue
- Example files or inputs, if relevant
- The potential security impact
- Any suggested mitigation or fix
Please avoid publicly disclosing the vulnerability until it has been investigated and, where necessary, a fix has been released.
Examples include:
- Arbitrary code execution
- Unsafe handling of specially crafted image, metadata, project, or sidecar files
- Path traversal or unintended file access
- Exposure of credentials, authentication tokens, or private information
- Vulnerabilities in Immich or Nextcloud communication
- Security issues involving third-party dependencies
- Bypasses of security-related restrictions
Normal application bugs, crashes without a security impact, feature requests, and usability problems should be reported through the regular GitHub issue tracker.
Security reports will be reviewed as soon as reasonably possible.
If the issue is confirmed, a fix will be developed before details are publicly disclosed whenever possible.
Thank you for helping keep FerrumPix and its users safe.