| Version | Supported |
|---|---|
| 0.1.x | ✅ Active support |
| < 0.1 | ❌ Not supported |
PixelSense interacts with monitor hardware through DDC/CI commands and reads ambient sensor data. A security vulnerability could potentially:
- Manipulate physical display hardware
- Access local configuration files
- Exploit the Tauri IPC boundary
We take every report seriously.
Do not open a public issue for security vulnerabilities.
Instead, please report vulnerabilities privately:
- GitHub Security Advisories (preferred): Use the Security Advisories feature to submit a private report
- Email: Contact the maintainers at the email listed in the repository
- Description of the vulnerability
- Steps to reproduce
- Affected versions
- Potential impact
- Suggested fix (if any)
| Action | Timeframe |
|---|---|
| Acknowledgment | Within 48 hours |
| Initial assessment | Within 5 business days |
| Fix development | Based on severity |
| Public disclosure | After fix is released |
PixelSense follows these security principles by design:
- Zero network access — The application makes no outbound connections
- No telemetry — No data collection of any kind
- Local-only storage — Configuration stored in local
.jsonfiles - Memory-only analysis — Screen content is analyzed in memory and never persisted
- Minimal permissions — Only hardware APIs required for brightness control are accessed
- Tauri IPC hardening — Frontend-to-backend communication is restricted to defined command endpoints
- Automated dependency updates via Dependabot
- Rust dependencies audited with
cargo audit - npm dependencies monitored for known vulnerabilities