Skip to content

Security: michael-L-i/voicebridge

SECURITY.md

Security Policy

Supported versions

Security fixes are made on the latest released version of VoiceBridge. Older releases are not maintained separately; users should update to the newest release before reporting a problem that may already be fixed.

Reporting a vulnerability

Please use GitHub's Report a vulnerability form on the repository's Security tab. This creates a private report that can be discussed and fixed before public disclosure.

Include, when possible:

  • the affected VoiceBridge and macOS versions;
  • the impact and a minimal reproduction;
  • whether the issue requires a malicious plugin, model, configuration, or local user; and
  • any suggested mitigation.

Do not include real voice recordings, transcripts, credentials, or other personal data unless they are essential and have been carefully redacted.

You should receive an acknowledgment within seven days. The maintainer will coordinate a fix and disclosure timeline based on severity and exploitability. Please allow a reasonable remediation period before publishing details.

For ordinary bugs and support questions, use the public issue tracker or GitHub Discussions instead.

There aren't any published security advisories