Skip to content

Security: chosen-man/driver-driver

Security

SECURITY.md

Security

Please do not publish access tokens, device codes, signing keys, keystores, or private repository details in an issue.

Driver Driver uses GitHub's OAuth Device Flow without a client secret. The OAuth client ID included in the Android build is public application configuration. Authorized access tokens are encrypted with an Android Keystore AES-GCM key and are not written to logs.

To report a security problem privately, contact Chosen Man Studio through https://chosenman.studio rather than opening a public issue.

There aren't any published security advisories