Skip to content

Security: KiloPack/life-diff

SECURITY.md

Security policy

Supported version

Security fixes are applied to the latest released version and the default branch.

Reporting a vulnerability

Please do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting for this repository and include:

  • the affected version and platform;
  • steps to reproduce with synthetic data;
  • the expected and observed impact; and
  • any suggested mitigation, if known.

Do not include real Life Diff backups, personal timeline data, signing credentials, or access tokens. If private vulnerability reporting is unavailable, open a minimal public issue asking the maintainer to enable a private contact channel without disclosing technical details.

Data protection scope

Life Diff stores workspace data in the local WebView profile and can export readable JSON backups. It does not claim to encrypt data at rest. Users are responsible for protecting their operating-system account, device, and exported backups.

There aren't any published security advisories