Whispr handles authentication material and encrypted communications, but it has not received an independent security audit. Treat current releases as experimental.
Security fixes are developed against the current main branch. Older commits,
forks, and unofficial binaries are not supported.
Use GitHub's private vulnerability reporting flow:
https://github.com/0xleitfader/whisprChat/security/advisories/new
Include:
- The affected server or client version and commit.
- The component, endpoint, or workflow involved.
- Reproduction steps using accounts and infrastructure you control.
- The expected and observed security boundary.
- Relevant logs with tokens, credentials, user data, and server addresses removed.
- A suggested fix, when available.
Do not publish active credentials, private user data, or exploitation details in a public issue. Do not test against deployments you do not own or have explicit permission to assess.
If private vulnerability reporting is unavailable, open a public issue that contains no technical exploit details and asks the maintainer to establish a private contact channel.
Configuration questions, unsupported platforms, and ordinary operational bugs can use public issues after all secrets and personal data are removed. A leaked secret is an incident: revoke or rotate it immediately rather than waiting for a code change.