Currently supported versions for security updates:
| Version | Supported |
|---|---|
| latest | ✅ |
| older | ❌ |
We take security seriously. If you discover a security vulnerability, please follow these steps:
Instead:
-
GitHub Security Advisory: Use private reporting at GitHub Security Advisories
-
Email fallback: If advisory reporting is unavailable, open a private maintainer contact request through GitHub Issues
-
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
-
Response Time:
- Initial response: Within 48 hours
- Status update: Within 7 days
- Fix timeline: Depends on severity
- Download APKs only from official GitHub releases
- Verify APK signatures match our certificate fingerprint
- Keep the app updated to the latest version
- Review permissions before installing
- Never commit sensitive data (API keys, tokens)
- Use environment variables for secrets
- Follow secure coding practices
- Keep dependencies updated
- Security fixes are released as soon as possible
- We credit researchers who report vulnerabilities (if desired)
- Details are disclosed after a fix is available
Git Store implements:
- HTTPS-only connections
- Secure token storage on device via encrypted storage wrappers
- No tracking or analytics
- Open source code for transparency
Thank you for helping keep Git Store secure! 🔒