Skip to content

Security: hsr88/mouzi

SECURITY.md

Security Policy

Mouzi watches folders and automatically moves files, so security and predictable file handling are important to the project.

Supported Versions

Security updates are provided for the latest released version of Mouzi. Please confirm that the issue still exists in the newest version before submitting a report.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or social media.

Use GitHub's private vulnerability reporting feature:

Report a vulnerability privately

Please include:

  • A clear description of the vulnerability.
  • The affected Mouzi version and operating system.
  • Steps required to reproduce the issue.
  • The potential impact.
  • Proof-of-concept files or code, if applicable.
  • Any suggested fix or mitigation.

Reports involving file paths, symbolic links, archive extraction, rule processing, unintended file operations, privilege boundaries, or code execution are particularly useful.

You should receive an initial response within seven days. Fix and disclosure timelines will depend on the severity and complexity of the issue.

Please allow reasonable time for the issue to be investigated and fixed before publishing details.

Safe Research

Good-faith security research is welcome when it:

  • Is performed on systems and files you own or are authorized to test.
  • Avoids accessing other people's data.
  • Does not disrupt services or distribute malicious files.
  • Gives the project a reasonable opportunity to address the issue.

Mouzi does not currently operate a paid bug bounty program. Security reports are still greatly appreciated, and researchers may be credited in the release notes if they wish.

There aren't any published security advisories