THE Collector is maintained on the latest main release line.
| Version line | Supported |
|---|---|
Latest (main / newest release tag) |
Yes |
| Older tags/releases | Best effort only |
Please use GitHub Security Advisories for private reporting:
If the advisory flow is unavailable, open a private maintainer contact via repository owner channels and include [SECURITY] in the subject.
Please include:
- Affected version (or commit SHA)
- Reproduction steps / proof of concept
- Expected impact and attack preconditions
- Suggested mitigation (if available)
- Initial triage acknowledgement: within 3 business days
- Severity assessment and remediation plan: within 7 business days
- Fix publication target:
- Critical/High: as fast as possible, target 7 days
- Medium: target 30 days
- Low: next planned hardening cycle
- Coordinate disclosure with maintainers until a fix is released.
- Do not publicly disclose exploit details before maintainers confirm remediation or mitigation.
- Credit will be provided in release notes unless you request anonymous disclosure.
- THE Collector is local-first and does not include a backend upload pipeline.
- Findings affecting extension permissions, data exposure, local storage handling, or release artifacts are in scope.