Skip to content

Security: the-sudipta/installor

Security

SECURITY.md

Security Policy

Supported versions

VersionSecurity support
Latest releaseSupported
Older releases and development snapshotsBest effort; upgrade may be required

Report a vulnerability privately

Use the repository's Security → Report a vulnerability function to open a private GitHub Security Advisory:

https://github.com/the-sudipta/installor/security/advisories/new

Include the affected version, operating system, reproduction steps, impact, and any suggested mitigation. Do not open a public issue for an unpatched vulnerability and do not include real credentials, private spreadsheets, or institutional data.

You can expect an initial acknowledgement when maintainer capacity permits. No fixed response or remediation deadline is promised. Coordinated disclosure timing will be discussed based on severity and the availability of a tested release.

Security boundaries

Installor orchestrates third-party installers and native package managers; it cannot guarantee the safety of software selected by a user. Prefer official HTTPS sources, publisher signatures, package-manager identifiers, and independently obtained checksums. Checksum equality detects a difference from an expected file but does not by itself establish publisher identity.

Unsigned community builds can legitimately trigger SmartScreen or Gatekeeper. Release signing and notarization are separate trust controls and are not claimed for v0.2.0.

There aren't any published security advisories