Skip to content

Security: quillpad/quillpad

Security

SECURITY.md

Security Policy

Supported Versions

Currently, the following versions of Quillpad are supported with security updates:

Version Supported
1.5.x
< 1.5

We recommend always using the latest version of Quillpad to ensure you have the latest security patches.

Reporting a Vulnerability

We take the security of Quillpad seriously. If you believe you have found a security vulnerability, please report it to us responsibly.

Please do not report security vulnerabilities via public GitHub issues.

Instead, please use the GitHub Security Advisory reporting feature to submit a private report.

Our Process

Once a report is received:

  1. We will acknowledge receipt of your report within 48 hours.
  2. We will investigate the issue and confirm the vulnerability.
  3. We will work on a fix.
  4. Once a fix is ready, we will release a new version and publish a Security Advisory.

We ask that you provide us with a reasonable amount of time to resolve the issue before making any information public.

Scope

The following are generally considered out of scope:

  • Issues related to rooting the device.
  • Issues requiring physical access to an unlocked device.
  • Theoretical vulnerabilities without a clear proof-of-concept.

There aren't any published security advisories