The latest released version of SideNotes receives security updates. Older versions are not supported.
If you find a security issue in SideNotes, please do not open a public GitHub issue. Instead, email the details to:
Please include:
- A clear description of the issue and its impact.
- Steps to reproduce (ideally with a minimal vault folder + the exact SideNotes version, OS, and architecture).
- Whether the issue has been disclosed elsewhere.
You can expect:
- An acknowledgement within 72 hours.
- A status update at least every 7 days while the issue is being triaged.
- A coordinated-disclosure timeline once a fix is ready, typically within 30 days of confirmation.
- Social engineering, physical attacks, or theft of an unlocked device.
- Issues that require the user to install a malicious vault folder from an untrusted source.
- Vulnerabilities in dependencies that are already publicly disclosed and have an open upstream advisory.
Researchers who disclose a confirmed issue responsibly will be credited in the release notes for the fixing version, unless they prefer to stay anonymous.