Skip to content

Security: hmlendea/dl-desktop

Security

SECURITY.md

Security Policy

This policy defines the process for responsible vulnerability reporting, coordinated remediation, and supported release channels for this repository.

πŸ“‘ Table of Contents

πŸ›‘οΈ Supported Versions

Use this table to indicate which project versions currently receive security maintenance.

Version Distribution Method Supported
Latest version FlatHub βœ…
Latest version AppImage ❌
Latest version AUR ❌
Latest version GitHub Releases ❌
Latest version Snap Store ❌
Latest version Unofficial third-party distribution channels ❌
Preceding versions Any distribution channel ❌

🚨 Reporting a Vulnerability

Please do not disclose suspected vulnerabilities publicly before maintainers have had an opportunity to validate and remediate them.

To report a vulnerability:

πŸ“Œ Scope

The subsequent report categories are in scope for this repository:

  • Electron application vulnerabilities within this repository's source code
  • Packaging and distribution artefacts maintained by this repository (FlatHub support scope)

The subsequent categories are out of scope unless explicitly stated to the contrary:

  • Vulnerabilities in third-party services or upstream Duolingo web infrastructure
  • Community-maintained distribution channels (AUR and Snap packaging)

πŸ“’ Disclosure Policy

This project follows coordinated disclosure:

  1. Vulnerabilities are investigated privately.
  2. A remediation plan is prepared and validated.
  3. Public disclosure is published after a fix, mitigation, or agreed risk decision is available.
  4. Credit is attributed in accordance with reporter preference and project policy.

πŸ™ Recognition

We appreciate responsible disclosure. Reporters who desire public attribution may be acknowledged in release notes, advisories, or a dedicated acknowledgements section.

There aren't any published security advisories