Security review is best effort. The public source snapshot tracks the current maintained code line unless this file says otherwise.
Do not open a public issue containing secrets, private phrases, clipboard contents, logs with personal data, signing material, API keys, certificates, provisioning profiles, or crash reports with sensitive data.
Use GitHub private vulnerability reporting if it is enabled for this repository. If it is not enabled, contact the maintainer at daniel@whtobe.com.
This policy covers the official Lazy Quips source repository and official builds. Fork maintainers are responsible for the security of their own changes, signing identities, release channels, and distributed binaries.
Please include:
- A concise description of the issue.
- Reproduction steps when possible.
- The affected source revision or app version.
- Whether the issue involves clipboard writes, local data storage, app launch behavior, global shortcuts, or macOS permissions.
There is no guaranteed response time. Reports are handled on a best-effort basis.
Please coordinate disclosure when practical, but this security policy is not a separate license restriction on GPL rights.