Security Policy
Reporting A Vulnerability
If you find a security issue, report it privately to the project maintainer.
- Do not open a public issue with exploit details.
- Do not include secrets, access tokens, private keys, or private datasets in your report.
- Include the affected file, script, launcher, or command path when possible.
- Include clear reproduction steps and the observed impact.
What To Avoid Posting Publicly
- API keys
- passwords
- internal network paths
- private customer or personal data
- local machine configuration files that contain secrets
Scope Notes
This project is a local Windows file utility. Review carefully before running sync, mirror, or builder scripts on real data.
No guaranteed response time is promised, but well-structured private reports are helpful and appreciated.