Skip to content

Security: logbie/notepad-plus-plus

Security

SECURITY.md

Security Policy

Scope

What you found Where to report
Issue present in official Notepad++ / likely affects everyone Prefer upstream project’s security process and maintainers; you may also CC the fork contact below
Issue only in Logbie fork changes / packaging / agent tooling Report privately to the fork maintainer (below)

Do not assume this fork is the official security contact for Notepad++.

Supported versions (fork)

Security fixes on this fork are applied at the maintainer’s discretion to the mainline branch and, when practical, to the latest fork tag. Older forks/tags may not receive backports unless explicitly stated here.

Upstream support policy is defined by the upstream project, not by this document.

Reporting a vulnerability (fork contact)

Please do not open a public issue for security vulnerabilities.

Report privately to:

bsbyrd@logbie.com

Include:

  • A description of the issue and its impact
  • Steps to reproduce or a proof-of-concept (if safe)
  • Affected versions / commit SHAs if known
  • Whether you believe it is upstream-shared or fork-only
  • Any suggested fix (optional)

You should receive an acknowledgment when the report is seen. Timing depends on maintainer availability (this is a maintained-in-the-open fork, not a 24/7 SOC).

GitHub private vulnerability reporting

If enabled on logbie/notepad-plus-plus, you may use GitHub’s private advisory flow. Prefer email if you are unsure.

Safe harbor (good-faith research)

Good-faith security research that:

  • Avoids privacy violations, service degradation, and data destruction
  • Does not exploit the issue beyond what is needed to demonstrate it
  • Reports findings promptly through an appropriate channel above

…is welcome. Do not use findings for extortion or public dump-before-report.

AI and agents

Do not instruct agents to:

  • Probe production systems you do not own or lack written authorization to test
  • Exfiltrate secrets, dumps, or personal data into chat/logs
  • Publish exploit details in public issues before coordinated disclosure
  • Write exploit PoCs into this repository

Defensive analysis and hardening patches are encouraged. Recent upstream work on UNC path credential leakage is an example of the kind of fix that belongs here and/or upstream.

Disclosure

The fork maintainer may publish advisories or release notes after a fix is available (or when disclosure is otherwise appropriate). Please allow reasonable time for a fix before public discussion of exploit details. Coordinate with upstream when the issue is shared.

There aren't any published security advisories