Report a vulnerability privately through GitHub: the repository's Security tab → Report a vulnerability. Please do not open a public issue for it.
Useful to include: the version (voltip-desktop --version), the platform, what an attacker can do,
and the steps to reproduce. You will get an answer within a week.
Only the latest release is supported while the project is below 1.0.
docs/threat-model.md describes what the pairing, the end-to-end encrypted channel and the relay
are designed to withstand, and what is out of scope.