Skip to content

Security: wealthfolio/wealthfolio-addons

Security

SECURITY.md

Security and Abuse Reports

Report privately: hello@wealthfolio.app

Do not open a public issue or pull request for any of the following. A public report tells everyone else how to exploit the problem before it can be handled.

Report privately:

  • a vulnerability in Wealthfolio, an official addon, or the addon runtime;
  • a community addon that behaves maliciously, exfiltrates data, or does something it did not declare;
  • a listing that infringes copyright, a trademark, or other rights;
  • a privacy problem — undisclosed collection, or data going somewhere the listing does not declare;
  • a listing that misrepresents its publisher or claims to be official.

Please include: the addon id, the repository URL, what you observed, how to reproduce it, and how you would like to be credited (or that you prefer not to be).

What happens next

Reports are read by the maintainer. Wealthfolio is a small project, so there is no service-level commitment, but:

  • credible, specific reports about a community listing may lead to the entry being hidden or removed while the report is looked at;
  • hiding a listing is a precaution, not a finding of wrongdoing;
  • Wealthfolio records its own reason internally whenever it hides a listing;
  • Wealthfolio does not promise to investigate, adjudicate between a reporter and a publisher, or reinstate a removed listing.

Community addons are published, distributed, and supported by their own publishers. Wealthfolio does not host their packages and cannot patch them. For a bug in a community addon, contact the publisher through the supportUrl in its listing.

Public issues

Use a public issue only for ordinary directory corrections — a dead repository link, a wrong description, a listing whose publisher has renamed the project.

There aren't any published security advisories