The Notepad has not published a stable release. Security fixes are currently made only on the active development branch. Local builds are unsigned, and no installer or automatic-update channel exists yet.
Use the repository's Security tab and choose Report a vulnerability when private vulnerability reporting is available.
If that option is unavailable, open a public issue containing only a request for a private reporting channel. Do not include exploit details, private notes, recovery files, credentials, or other sensitive information in a public issue.
Include these details in the private report when possible:
- affected revision or build;
- Windows version;
- clear reproduction steps;
- security or data-loss impact;
- whether the issue is already public;
- a minimal proof of concept with personal data removed.
Please allow maintainers a reasonable opportunity to investigate and prepare a fix before public disclosure. The project aims to acknowledge a complete report within seven days, but this is a volunteer project and cannot guarantee a response or remediation deadline.
Reports are especially useful when they involve:
- loss, corruption, or unintended disclosure of note contents;
- unsafe handling of files, paths, links, or imported content;
- recovery data being exposed to another Windows user;
- command or code execution from untrusted note content;
- persistence or startup behavior that occurs without clear consent;
- update, packaging, or signature problems once those features exist.
Normal editing is intended to work locally without an account or required network connection. A change that introduces network access must document its purpose and user control.