Only the latest published version of Annoteca receives security updates.
| Version | Supported |
|---|---|
| latest | ✅ |
| older | ❌ |
If you discover a security vulnerability in Annoteca, please report it privately so it can be fixed before public disclosure:
- DO NOT open a public GitHub issue for security vulnerabilities.
- Open the repository's Security tab and click Report a vulnerability, or use this direct link: https://github.com/ckelsoe/obsidian-annoteca/security/advisories/new
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
Reports submitted through GitHub private vulnerability reporting are visible only to you and the maintainer until an advisory is published.
- Acknowledgment within 48 hours
- Assessment and response within 7 days
- Security patch released as soon as possible
- Credit given to reporter (unless you prefer to remain anonymous)
Describe what the plugin does and does not do that's relevant to security: file reads, file writes, network access (none expected), external commands, etc.