We appreciate responsible disclosures that help keep Vidra safe for everyone.
- Do not open a public issue to report security problems.
- Send an email to 7k9mc4urn@mozmail.com with the subject
Security Report. - Please include:
- A clear description of the vulnerability and its potential impact.
- Steps to reproduce it (commands, logs, screenshots).
- Any temporary mitigation you have discovered.
- Please allow a timeframe of 7 to 10 business days to receive an initial response. If the problem is critical, mark it as
URGENTin the subject line.
- All code, media assets, and tools in this repository.
- Official Vidra builds distributed by chomusuke.dev.
- Third-party dependencies are covered only to the extent that Vidra's integration exposes an additional or unusual risk.
- Do not execute destructive testing against production services owned by third parties.
- Avoid accessing user data; if unavoidable, explain what was accessed and securely delete it immediately.
- Keep vulnerability details confidential until a fix is released or until chomusuke.dev provides you with written approval.
Thank you for helping us maintain a modern and secure collaborative space.