Please do not disclose an unpatched vulnerability in a public issue.
Send a concise report to support@studiojin.dev with:
- the affected version or commit;
- the macOS version and distribution channel;
- reproduction steps or a proof of concept;
- the expected and observed impact; and
- any suggested mitigation.
Do not include real credentials, personal files, or other people's data. Use placeholders or a minimal local reproduction.
StudioJin will acknowledge the report when practical, investigate it, and coordinate disclosure or a fix based on severity and release constraints. No bounty program or guaranteed response time is currently offered.
Security fixes normally target the latest released version and the current main branch. Older versions may be asked to update before receiving a separate fix.
Official releases are published through StudioJin's GitHub Releases and Mac App Store channels. Forks and derivative builds may have different security and update policies; verify their publisher and source before installation.