Skip to content

Security: HafidIdrissi/Time-Tracker

SECURITY.md

Security Policy

Local Time Tracker records foreground application names and window titles. Those titles can contain sensitive information, so privacy and safe reporting are part of the security model.

Supported versions

Security fixes are applied to the latest published release. Users should update to the newest version available on the Releases page.

Report a vulnerability privately

Please use GitHub's private vulnerability reporting to report a suspected vulnerability.

Include:

  • the affected version;
  • the Windows version and installation method;
  • a clear description of the impact;
  • minimal reproduction steps or a proof of concept;
  • suggested remediation, if known.

Do not include real activity databases, personal reports, private window titles, credentials, signing material, or other people's data. Create a minimal example with demonstration data instead.

The maintainer aims to acknowledge a complete report within five business days and will provide updates when the investigation materially changes. Resolution time depends on severity and complexity.

Public disclosure

Please allow time for investigation and a fixed release before publishing technical details. The maintainer will coordinate disclosure and credit with the reporter where practical.

For ordinary bugs and feature requests, use the public issue tracker.

There aren't any published security advisories