Skip to content

Security: ZaidNAlAsali/ZFileConverter

SECURITY.md

Security policy

Supported version

Security fixes target the latest published ZFileConverter release.

Reporting a vulnerability

Please do not disclose a suspected vulnerability in a public issue. Use GitHub's private vulnerability-reporting flow:

https://github.com/ZaidNAlAsali/ZFileConverter/security/advisories/new

Include:

  • the affected version;
  • a concise reproduction;
  • expected impact;
  • whether Explorer, shell registration, installer elevation, file paths, or conversion tools are involved;
  • any proposed mitigation.

Do not include real private documents, media, credentials, certificates, or sensitive system data. A minimal synthetic reproduction is preferred.

Scope

Reports involving unsafe path handling, unintended source-file changes, shell-extension stability, installer privilege boundaries, update integrity, or command injection are especially valuable.

There aren't any published security advisories