Skip to content

Security: munzzyy/blot

Security

SECURITY.md

Security policy

Blot exists to make redaction certain, so reports get taken seriously and answered fast.

Reporting

Email Munzzyy1@proton.me, or use GitHub's private vulnerability reporting on this repository. You will get an answer within 72 hours.

Especially interested in:

  • Any way to extract text, form data, annotations, or metadata from a Blot output (this is the core promise; treat any counterexample as critical).
  • A document class that should be refused but is not, or renders differently than a mainstream viewer shows it.
  • Any network traffic from the app at all.
  • Crashes or hangs on hostile PDF input.

Scope notes

  • Content you chose not to ink shipping in the output is by design; Blot covers what you pick.
  • Visual-layout fingerprinting of the output is documented in the threat model, not a vulnerability.

No bounty

There is no money behind this project. What you get is a fast fix, credit in the changelog if you want it, and a tool that stays trustworthy.

There aren't any published security advisories