Sable works with real personal libraries and optional contributor accounts. Please treat both as sensitive.
- The repository contains no production tokens, sessions, passwords, or API keys.
- Credentials entered in Settings are stored in the macOS Keychain.
- Do not paste credentials into issues, screenshots, logs, fixtures, source files, or pull requests.
- Use your own MangaBaka, Roler, TMDB, or TVDB access where a workflow asks for it.
If you accidentally commit a credential, revoke it with the provider first. Removing it from a later commit does not remove it from Git history.
Before sharing a Sable report, inspect it for local paths, filenames, series names, provider IDs, and account-related details. Use synthetic fixtures in bug reports whenever possible.
Please report security or privacy problems privately through GitHub's security advisory feature for this repository. Include the affected app, the smallest safe reproduction, and whether real files or credentials may be at risk. Do not open a public issue for an unpatched credential leak, destructive file operation, or account-authentication flaw.
Sable is designed around preview, explicit selection, confirmation, and receipts. Changes that weaken those boundaries need focused tests and a clear recovery story.