Skip to content

Security: goldwav/The-Notepad

Security

SECURITY.md

Security Policy

Supported versions

The Notepad has not published a stable release. Security fixes are currently made only on the active development branch. Local builds are unsigned, and no installer or automatic-update channel exists yet.

Report a vulnerability

Use the repository's Security tab and choose Report a vulnerability when private vulnerability reporting is available.

If that option is unavailable, open a public issue containing only a request for a private reporting channel. Do not include exploit details, private notes, recovery files, credentials, or other sensitive information in a public issue.

Include these details in the private report when possible:

  • affected revision or build;
  • Windows version;
  • clear reproduction steps;
  • security or data-loss impact;
  • whether the issue is already public;
  • a minimal proof of concept with personal data removed.

Please allow maintainers a reasonable opportunity to investigate and prepare a fix before public disclosure. The project aims to acknowledge a complete report within seven days, but this is a volunteer project and cannot guarantee a response or remediation deadline.

Relevant security boundaries

Reports are especially useful when they involve:

  • loss, corruption, or unintended disclosure of note contents;
  • unsafe handling of files, paths, links, or imported content;
  • recovery data being exposed to another Windows user;
  • command or code execution from untrusted note content;
  • persistence or startup behavior that occurs without clear consent;
  • update, packaging, or signature problems once those features exist.

Normal editing is intended to work locally without an account or required network connection. A change that introduces network access must document its purpose and user control.

There aren't any published security advisories