Skip to content

Security: ckelsoe/obsidian-annoteca

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest published version of Annoteca receives security updates.

Version Supported
latest
older

Reporting a Vulnerability

If you discover a security vulnerability in Annoteca, please report it privately so it can be fixed before public disclosure:

  1. DO NOT open a public GitHub issue for security vulnerabilities.
  2. Open the repository's Security tab and click Report a vulnerability, or use this direct link: https://github.com/ckelsoe/obsidian-annoteca/security/advisories/new
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

Reports submitted through GitHub private vulnerability reporting are visible only to you and the maintainer until an advisory is published.

What to expect:

  • Acknowledgment within 48 hours
  • Assessment and response within 7 days
  • Security patch released as soon as possible
  • Credit given to reporter (unless you prefer to remain anonymous)

Security Considerations

Describe what the plugin does and does not do that's relevant to security: file reads, file writes, network access (none expected), external commands, etc.

There aren't any published security advisories