Security fixes target the latest revision of main. Older source revisions and
previous APKs are not maintained as separate supported release lines.
When private vulnerability reporting is available on GitHub, use the
repository's Report a vulnerability form. Until then, email
yang@chihum.dev. Do not open a public issue for a suspected vulnerability.
Useful reports include the affected revision, platform, impact, reproduction steps, and a minimal non-copyrighted test file when one is required. Examples in scope include malicious EPUB parsing, archive or path traversal, unintended local-file exposure, OAuth credential handling, and Google Drive sync data isolation.
Reports are handled on a best-effort basis. The project does not promise a response or remediation deadline. Please allow time for investigation before public disclosure.