Skip to content

Security: tanjiro184/SereinMac

SECURITY.md

Security policy

Serein’s security boundary includes filesystem target planning, path validation, Recovery journals, restore, fixed commands, macOS permissions, critical confirmation, build signing, and release notarization.

Supported versions

Version Security fixes
0.1.x technical preview Supported on a best-effort basis
Unreleased development branches No support guarantee

Until a Developer ID-signed and Apple-notarized binary release is published, source builds and local ad hoc packages are technical-preview artifacts.

Report privately

Use GitHub’s private vulnerability reporting for the repository:

Report a vulnerability privately

If that form is unavailable, open a minimal non-sensitive issue asking the maintainer to enable a private channel. Do not include exploit details, personal paths, secrets, certificates, Recovery manifests, or command output in a public issue.

Include, where safe:

  • affected commit/version and macOS version;
  • hardware architecture;
  • module ID and operation type;
  • simulation or real execution;
  • expected and actual behavior;
  • minimal reproduction using disposable fixture data;
  • whether target data moved, disappeared, or became unrestorable;
  • sanitized logs and crash traces;
  • suggested severity and impact.

Never test a report against someone else’s Mac, account, repository, or cloud service without explicit authorization.

Response targets

This community project aims to:

  • acknowledge a report within 5 business days;
  • confirm triage or request more detail within 10 business days;
  • coordinate a fix and disclosure timeline according to severity.

These are targets, not contractual service-level guarantees.

High-priority classes

  • a plan executing a path not shown to the user;
  • a target escaping its catalogue PathRule;
  • symlink traversal or dangerous filesystem race;
  • a move without a usable write-ahead manifest;
  • restore reading a source outside Recovery;
  • critical action running in a mixed batch or without all gates;
  • arbitrary command, argument, environment, or shell injection;
  • protected-location or TCC bypass;
  • telemetry/network behavior not disclosed in PRIVACY.md;
  • release certificate, Keychain, notary credential, or workflow-secret exposure;
  • an artifact labeled notarized when its ticket/signature is invalid;
  • update/supply-chain compromise if an updater is added later.

Safe research fixtures

Use a temporary fake home and temporary directory, as the self-test does. Do not aim destructive tests at real personal folders. Critical Finder Trash and Recovery purge tests should use disposable accounts or virtual machines with independent backups.

Release integrity

Public binaries are trustworthy only when all of the following match the release notes:

  • source tag;
  • SHA-256;
  • expected Developer ID owner and Team ID;
  • hardened-runtime timestamped signature;
  • Apple notary status Accepted;
  • stapled ticket;
  • provenance attestation.

See docs/RELEASING.md.

Disclosure credit

Serein will credit reporters who want recognition, unless legal, privacy, or safety constraints prevent it. Anonymous reports are welcome.

There aren't any published security advisories