Security fixes are provided for the latest published BarKeep release. Upgrade to the newest release before reporting a problem that may already be fixed.
Please use GitHub private vulnerability reporting. Do not open a public issue for an undisclosed vulnerability.
Include:
- The affected BarKeep version and installation method
- Your macOS and Busy Bar firmware versions
- Reproduction steps or a proof of concept
- The expected security impact
- Any suggested mitigation
Do not include real API passwords, OAuth tokens, signing credentials, private notifications, or other personal data. Replace them with clearly marked test values.
You will receive a best-effort acknowledgement and follow-up through the private advisory. Please allow time for a fix and coordinated disclosure before publishing details.
This policy covers code and release artifacts published by the
unipheas/barkeep and unipheas/homebrew-barkeep repositories.
Busy Bar firmware, Busy cloud services, Slack, macOS, Homebrew, Claude, Codex, and ChatGPT are third-party products. Report vulnerabilities in those products to their respective maintainers unless BarKeep's code is the cause.
Ordinary bugs, feature requests, and documentation corrections can be filed through the public issue tracker.