Please do not open a public issue for vulnerabilities involving command execution, pairing, TLS identity, update signing, or exposure of phone data. Use GitHub's Report a vulnerability private reporting feature for this repository.
Do not attach real messages, phone numbers, notifications, files, pairing codes, private keys, or certificates. Provide a minimal reproduction with sanitized logs and the affected Ping, macOS, Android, and KDE Connect versions.
Ping is beta software. Only the newest published release is expected to receive security fixes.