Thanks for helping keep Ghost Apps and its users safe. Please don't report security issues in public GitHub issues, discussions, or pull requests.
Use either of these:
- GitHub: open a private report from the affected repository's Security → Report a vulnerability page.
- Email: ghost@ghostapps.rocks, ideally
encrypted with our PGP key:
3239 DF00 5BDF 2CD2 7898 57AF 59F8 42F7 3BAF 2A8D(keys.openpgp.org · ghostapps.rocks/pgp.asc)
Please include the affected app and version, steps to reproduce, and the impact you expect.
We're a small team, so we'll do our best to acknowledge your report within a few days and keep you updated as we work on a fix. Please give us a reasonable amount of time to release a fix before disclosing the issue publicly.
Only the latest release of each app receives security fixes.