EaseHub is a trusted local GNOME Shell extension. It can spawn terminals, request polkit
authentication for package updates, adjust per-user sudo timeout via visudo-validated
drop-ins, and trigger an X11 shell reload through GNOME's own Alt+F2 path. Install only
from official GitHub releases
with UUID comfort-control@nickotmazgin.
Terminal emulator preferences are restricted to a known whitelist. Package upgrades and
Flatpak updates require confirmation when confirm-dangerous is enabled (default).
We actively support security updates for the following versions of Comfort Control (EaseHub):
| Version | Supported |
|---|---|
| Latest | ✅ |
| < 1.0 | ❌ |
We take the security of Comfort Control (EaseHub) seriously. If you discover a security vulnerability, please report it responsibly.
Please do NOT create a public GitHub issue for security vulnerabilities.
Instead, please email us directly at:
- Email: nickotmazgin.dev@gmail.com
- Subject:
[SECURITY] Comfort Control EaseHub - Vulnerability Report
Please include the following information in your report:
- Description: A clear description of the vulnerability
- Steps to Reproduce: Detailed steps to reproduce the issue
- Impact: What an attacker could achieve with this vulnerability
- GNOME Shell Version: Which version(s) are affected
- System Information: OS, desktop environment, and relevant system details
- Proof of Concept: If available, include screenshots or code snippets
- Acknowledgment: We will acknowledge receipt within 48 hours
- Initial Assessment: We will provide an initial assessment within 5 business days
- Resolution: We aim to resolve critical vulnerabilities within 30 days
- Disclosure: We will coordinate with you on responsible disclosure timing
This security policy covers vulnerabilities in:
- Extension code and logic
- Configuration and settings handling
- Integration with GNOME Shell APIs
- Package management functionality
- Screenshot handling capabilities
- System power management features
The following are generally not considered security vulnerabilities:
- Issues requiring physical access to an unlocked system
- Vulnerabilities in third-party dependencies (please report to upstream)
- Issues requiring significant user interaction or social engineering
- Performance issues without security implications
We appreciate security researchers who help make Comfort Control (EaseHub) safer for everyone. With your permission, we'll acknowledge your contribution in:
- Security advisory (if published)
- Project contributors list
- Release notes for the fix
- Always install from official sources:
- Verify extension UUID:
comfort-control@nickotmazgin
- Keep your GNOME Shell and system updated
- Review extension permissions before installation
- Monitor extension behavior after installation
- Report any unexpected system behavior
- Use secure authentication methods (like
pkexec) for system operations - Regularly review and audit enabled extensions
- Limit extension permissions when possible
For security-related questions or concerns:
- Security Issues: nickotmazgin.dev@gmail.com
- General Support: GitHub Issues
Last updated: June 2026