Skip to content

Security: QuantumShieldLabs/qsl-desktop

SECURITY.md

Security Policy

Reporting a Vulnerability

Use GitHub's private vulnerability reporting / Security Advisories for this repository when available. Do not open a public issue for security-sensitive reports.

If private vulnerability reporting is unavailable, open a minimal public issue without exploit details and state that you can share additional information privately with maintainers.

Scope

This repository contains the in-development desktop client for the QSL protocol project (see README.md). It is pre-release: the application builds and runs, and it currently covers the local vault/identity/unlock lifecycle, relay configuration, and the invite create/review/revoke/redeem flow — there is no messaging. Report any issue that impacts the confidentiality, integrity, or availability of the artifacts in this repository, including the running client.

Protocol-level reports (specifications, cryptography, the qsc client) belong to the qsl-protocol repository and its security policy.

There aren't any published security advisories