Skip to content

Security: chintanmahida/Deck

Security

SECURITY.md

Security Policy | 安全政策

中文版

Supported Versions

Version Supported
1.x.x
< 1.0

Reporting a Vulnerability

We take security seriously. If you discover a security vulnerability within Deck, please follow these steps:

Do NOT

  • Open a public GitHub issue
  • Disclose the vulnerability publicly before it's fixed
  • Exploit the vulnerability

Do

  1. Email us directly at [email protected] with:

    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Any suggested fixes (optional)
  2. Use a descriptive subject line like "Security Vulnerability in Deck"

  3. Allow time for response - We aim to respond within 48 hours

What to Expect

  1. Acknowledgment: We'll confirm receipt within 48 hours
  2. Assessment: We'll assess the vulnerability and determine severity
  3. Fix Development: We'll develop and test a fix
  4. Release: We'll release a patched version
  5. Disclosure: After the fix is released, we'll publicly acknowledge the vulnerability and credit you (if desired)

Scope

The following are in scope:

  • Deck macOS application
  • Any data handling or storage mechanisms
  • Authentication/authorization (for Pro features)

Out of Scope

  • Social engineering attacks
  • Physical attacks
  • Denial of service attacks
  • Issues in dependencies (report to the dependency maintainer)

Security Best Practices for Users

  1. Download from official sources only - GitHub Releases or our website
  2. Verify checksums - Check SHA256 checksums before installing
  3. Keep Deck updated - Install security updates promptly
  4. Review permissions - Only grant necessary permissions

中文版

支持的版本

版本 支持状态
1.x.x
< 1.0

报告漏洞

我们非常重视安全问题。如果你在 Deck 中发现安全漏洞,请按以下步骤操作:

请勿

  • 公开提交 GitHub Issue
  • 在漏洞修复前公开披露
  • 利用该漏洞

  1. 直接发送邮件[email protected],包含:

    • 漏洞描述
    • 复现步骤
    • 潜在影响
    • 建议的修复方案(可选)
  2. 使用描述性的邮件主题,如 "Deck 安全漏洞"

  3. 等待回复 - 我们会在 48 小时内回复

处理流程

  1. 确认收到:48 小时内确认
  2. 评估:评估漏洞并确定严重程度
  3. 修复开发:开发并测试修复方案
  4. 发布:发布修复版本
  5. 披露:修复发布后,我们会公开致谢(如你愿意)

范围内

  • Deck macOS 应用程序
  • 任何数据处理或存储机制

范围外

  • 社会工程攻击
  • 物理攻击
  • 拒绝服务攻击
  • 依赖项中的问题(请向依赖项维护者报告)

用户安全最佳实践

  1. 仅从官方渠道下载 - GitHub Releases 或我们的官网
  2. 验证校验和 - 安装前检查 SHA256 校验和
  3. 保持更新 - 及时安装安全更新
  4. 审查权限 - 仅授予必要的权限

感谢你帮助保护 Deck 和用户的安全!

There aren’t any published security advisories