Security fixes are made for the latest 0.2.x release. Older versions should
be upgraded before reporting a problem.
Please do not open a public issue for a suspected vulnerability. Use GitHub's
private vulnerability reporting for this repository. If that is unavailable,
email r.ralmuto@gmail.com with:
- the affected version;
- a concise description and reproduction steps;
- the possible impact; and
- any suggested mitigation.
You should receive an acknowledgement within seven days. Please allow time for a fix to be prepared before disclosing the issue publicly.
Mnemos stores private memory data locally. Reports involving unexpected file access, scope leakage between people or projects, unsafe command execution, or data loss are treated as security-sensitive.