Security fixes land on main and ship in the next tagged release. Installers are
published as Emc²-<version>-<os>-<arch>.<ext>.
| Version | Supported |
|---|---|
| 0.1.3 and later | Yes |
| Earlier | No |
Report privately through GitHub's private vulnerability reporting (Security → Advisories → Report a vulnerability). Include the version, the platform, and the steps or proof of concept that show the problem.
Do not open a public issue for a vulnerability, and do not include mail content, addresses, account names or credentials in a report. A reproduction against a throwaway profile is easier to act on than one against real mail.
This is a volunteer project with no bug bounty. Expect an acknowledgement within a few days and either a fix or an explanation of the risk in the next release.
settings.env,
key.protected, and the encrypted mail store.