Skip to content

Security: SebRoLENS/VitalChronicle

Security

SECURITY.md

Security Policy

Supported version

Security fixes are provided for the latest VitalChronicle release.

Reporting a vulnerability

Do not open a public issue containing OAuth credentials, access tokens, health records, database files, or other sensitive personal information. Send a minimal private report to sebastiano.romi@gmail.com with the affected version, operating system, impact, and safe reproduction steps.

For ordinary bugs that do not expose sensitive information, use the public issue tracker.

Release trust

Official files are published only through this repository's GitHub Releases. Every release includes SHA-256 checksums. Linux AppImages are attested through GitHub Actions; Windows and macOS packages are currently unsigned by paid platform certificates.

There aren't any published security advisories