This policy defines the process for responsible vulnerability reporting, coordinated remediation, and supported release channels for this repository.
Use this table to indicate which project versions currently receive security maintenance.
| Version | Distribution Method | Supported |
|---|---|---|
| Latest version | FlatHub | β |
| Latest version | AppImage | β |
| Latest version | AUR | β |
| Latest version | GitHub Releases | β |
| Latest version | Snap Store | β |
| Latest version | Unofficial third-party distribution channels | β |
| Preceding versions | Any distribution channel | β |
Please do not disclose suspected vulnerabilities publicly before maintainers have had an opportunity to validate and remediate them.
To report a vulnerability:
- GitHub Security Advisories
- Contact the maintainers directly
The subsequent report categories are in scope for this repository:
- Electron application vulnerabilities within this repository's source code
- Packaging and distribution artefacts maintained by this repository (FlatHub support scope)
The subsequent categories are out of scope unless explicitly stated to the contrary:
- Vulnerabilities in third-party services or upstream Duolingo web infrastructure
- Community-maintained distribution channels (AUR and Snap packaging)
This project follows coordinated disclosure:
- Vulnerabilities are investigated privately.
- A remediation plan is prepared and validated.
- Public disclosure is published after a fix, mitigation, or agreed risk decision is available.
- Credit is attributed in accordance with reporter preference and project policy.
We appreciate responsible disclosure. Reporters who desire public attribution may be acknowledged in release notes, advisories, or a dedicated acknowledgements section.