Security fixes are prioritized for the current stable PaperRoute release and active development line.
Please do not publish suspected vulnerabilities, sensitive local paths, manuscript content, credentials, tokens, or private research data in a public GitHub issue.
Send suspected vulnerability reports privately to Joshua Uhalt at Josh.Uhalt@gmail.com. Do not include private research data unless needed and explicitly agreed; start with a minimal, anonymized description.
Useful reports include:
- the affected PaperRoute version;
- the relevant workflow or component;
- clear reproduction steps;
- expected and observed behavior;
- the potential impact; and
- any suggested mitigation.
PaperRoute is local-first, but features involving files, imports, external metadata services, update infrastructure, and local persistence should still be treated as security-sensitive.