Skip to content

Security: dortanes/ravenpass

SECURITY.md

Security policy

Reporting a vulnerability

Report vulnerabilities privately through GitHub security advisories. Do not open a public issue.

Include:

  • the affected app and version, and the platform and OS version;
  • what an attacker can do and what they need (local access, a malicious website, a copied vault file);
  • steps or a proof of concept that reproduces it.

You will get an acknowledgement within seven days. Please keep the report private until a fix is released.

Supported versions

Only the latest release receives security fixes.

Scope

In scope: the vault format and its encryption, unlock and recovery, the link between the Chrome extension and the Mac app, autofill on macOS and Android, and the release artifacts.

Out of scope: an attacker who already controls the unlocked device, its screen or clipboard; loss of a vault file that has no backup.

There aren't any published security advisories