Prune deletes files. We treat every bug that can cause unintended removal as a security issue.
Only the latest release receives fixes.
Please do not open a public issue for problems that could lead to data loss or privilege
escalation. Use GitHub's private vulnerability reporting
(Security → Report a vulnerability) on bonjin-app/prune. You will get an acknowledgement
within 72 hours.
Include:
- OS and version
- Prune version (
Settings → About) - Steps to reproduce, ideally against a temporary directory
- Whether real files were affected
These properties are enforced in crates/prune-core and covered by tests. A change that
weakens any of them requires a security review.
- Whitelist, not blacklist. Removal is only possible inside the user's home directory and the system temp directory. Everything else is refused before any I/O happens.
- Protected paths. System directories, the home directory itself,
~/Library,~/Documents,~/Desktop,~/.ssh, keychains, mail, photos, iCloud and Windows equivalents are never removable, even when inside the whitelist. - No raw paths over IPC for deletion. The frontend sends target ids from a scan and a plan id from a preview. Paths are resolved and re-validated inside the engine right before removal.
- Dry run first. A
CleanupPlanis always produced and shown before anything is removed. - Trash by default. Permanent deletion is opt-in and visually distinct.
- Local only. Prune has no network code, no telemetry, and no accounts. The operation log never leaves the machine.