If you find a security vulnerability, please report it responsibly:
- Do NOT open a public issue
- Use GitHub's private vulnerability reporting
- Include: description, steps to reproduce, potential impact
- Go to: https://github.com/file-bricks/WinStorePackager/security/advisories/new
- Fill out the form (title, description, severity, affected versions)
- Submit privately (not visible to public until disclosed)
We will respond as soon as possible.
- MSIX packaging
- Manifest generation
- Keyring credentials
- Host-local runtime settings and logs
Certificate passwords are stored only through the operating-system Keyring. Publisher IDs, certificate paths, SDK paths, settings, and logs are kept outside the source checkout under the host-local runtime directory. A legacy checkout-local settings file is migrated only after JSON validation and atomic readback; existing runtime settings are never overwritten.
As a solo project, response times may vary. Critical issues will be prioritized. Please allow reasonable time before public disclosure.