Security fixes are provided for the latest published SafeVault release.
Please do not open a public issue for a suspected vulnerability.
Use GitHub's Report a vulnerability option on the repository Security page to submit details privately. Include:
- the affected SafeVault version;
- operating system and installation method;
- reproduction steps or a minimal proof of concept;
- the security impact you observed;
- any suggested mitigation, if known.
You should receive an acknowledgement within seven days. Please allow time for investigation and a coordinated fix before public disclosure.
SafeVault is a local file-protection tool, not malware containment or a security boundary for untrusted code. Reports should distinguish product vulnerabilities from documented limitations in the Safety Model.