Skip to content

Security: zw3rk/peaklights

Security

SECURITY.md

Security

Peak Lights is an offline schedule calculator.

  • It makes no network requests.
  • It reads no API keys and stores no credentials.
  • It has no telemetry.
  • Official provider pages open in the browser only after an explicit menu command.
  • Custom rules live in ~/Library/Application Support/PeakLights/.
  • Invalid custom JSON produces gray/? lights, never a silent fallback to bundled green.

Local .app builds are ad-hoc signed unless you set CODESIGN_IDENTITY. GitHub Actions artifacts are the same: not Developer-ID signed, not notarized.

Report a vulnerability

Email Moritz Angermann <moritz@zw3rk.com>.

Do not open a public GitHub issue while a report is still private. Include the version (CFBundleShortVersionString) and how to reproduce.

There aren't any published security advisories