Security fixes are made for the current main branch and the most recent
published release once releases begin. Older revisions, forks, and unsupported
platform configurations may receive guidance, but are not maintained security
targets.
Please report suspected vulnerabilities privately through GitHub Private Vulnerability Reporting. Do not open a public issue, discussion, or pull request before a fix is available.
Include the affected version or commit, operating system, impact, clear reproduction steps or a minimal proof of concept, and any suggested mitigation. Remove personal information, credentials, and other sensitive data from the report. If a report relates to a dependency, please also report it to that dependency's maintainers when appropriate.
We aim to acknowledge valid reports within seven days, assess their impact, and work with the reporter on a fix and coordinated disclosure. We may request additional detail to reproduce the issue. Please give us a reasonable chance to ship a fix before public disclosure.
Unfocus is local-first: reports involving unexpected network access, telemetry, or exposure of local data are in scope, as are issues in the application, packaging and release scripts, and repository automation.
Please avoid accessing, changing, or exfiltrating data beyond what is needed to demonstrate the issue. Once a fix is available, we will publish a GitHub Security Advisory when the report warrants one and credit the reporter unless they prefer to remain anonymous.