mirror of
https://github.com/abue-ammar/tinycast.git
synced 2026-10-02 00:04:44 +08:00
* Add contributor, license and security guidelines Adds CONTRIBUTING.md, CONTRIBUTOR_LICENSE_AND_FEEDBACK_AGREEMENT.md and SECURITY.md, and renames CLAUDE.md to AGENTS.md so every coding agent reads the same instructions regardless of platform. CLAUDE.md stays as a stub that imports it. CONTRIBUTING.md states the non-negotiables up front: the 100 MB RAM ceiling, zero leaks, design taken from the existing tokens, and no bloat. Visual changes require a side-by-side before/after video in the PR. README.md gains Discord and hire-me badges, a Contributing pointer and a Contributors section. The contributor image is capped to one row so it can't grow as people join. * Add minimal GitHub issue templates Bug Report and Feature request as YAML forms, plus a config that keeps blank issues enabled and points questions at Discord and vulnerabilities at private advisories. Three required fields on bugs (what happened, version + channel, macOS version) matching what CONTRIBUTING already asks for; two on features, the second asking why it earns its place so scope is settled at filing time. * Update CLAUDE.md to clarify instructions
1.2 KiB
1.2 KiB
Security Policy
Reporting a Vulnerability
Report privately through GitHub: Security tab → Report a vulnerability.
Include your macOS version, the Tinycast version and channel, reproduction steps, and the impact. Please don't disclose publicly until it's fixed.
We'll respond as quickly as we can and keep you posted.
Supported Versions
Current stable and beta only. Update (brew upgrade --cask tinycast) before reporting.
Scope
Of particular interest:
- Accessibility (TCC) — anything that widens what the paste grant enables.
- Clipboard history — text and images cached on disk; unintended exposure or capture.
- Network — Tinycast is offline by default and every networked feature is consent-gated. A path that reaches the network without consent, or survives consent being withdrawn, is high severity.
- Hotkeys — the in-house hotkey stack and the Input Monitoring grant.
- Signing and distribution — the DMG and Homebrew cask chain.
Out of scope: builds being self-signed rather than notarized (known, see
docs/signing.md), and anything needing existing code execution or admin rights on
the machine.