Only the latest release receives security updates.
If you discover a security vulnerability in Textonom, please report it privately by opening a GitHub Security Advisory at:
https://github.com/Netroforge/textonom/security/advisories/new
Please do not open a public issue for security vulnerabilities.
We will acknowledge your report within 48 hours and work on a fix. Once the fix is released, we will credit you in the release notes (unless you prefer to remain anonymous).
Security reports are welcome for:
- Code execution vulnerabilities in the transformation engine (the main security-sensitive surface)
- Remote code execution via update process
- Data leakage through clipboard or file operations
- IPC bridge vulnerabilities
Non-security bugs should be filed as regular GitHub issues.