Files
Abue Ammar 1fa17517e8 Add contributor, license and security guidelines (#61)
* Add contributor, license and security guidelines

Adds CONTRIBUTING.md, CONTRIBUTOR_LICENSE_AND_FEEDBACK_AGREEMENT.md and
SECURITY.md, and renames CLAUDE.md to AGENTS.md so every coding agent reads
the same instructions regardless of platform. CLAUDE.md stays as a stub that
imports it.

CONTRIBUTING.md states the non-negotiables up front: the 100 MB RAM ceiling,
zero leaks, design taken from the existing tokens, and no bloat. Visual
changes require a side-by-side before/after video in the PR.

README.md gains Discord and hire-me badges, a Contributing pointer and a
Contributors section. The contributor image is capped to one row so it can't
grow as people join.

* Add minimal GitHub issue templates

Bug Report and Feature request as YAML forms, plus a config that keeps blank
issues enabled and points questions at Discord and vulnerabilities at private
advisories.

Three required fields on bugs (what happened, version + channel, macOS
version) matching what CONTRIBUTING already asks for; two on features, the
second asking why it earns its place so scope is settled at filing time.

* Update CLAUDE.md to clarify instructions
2026-07-28 15:55:29 +06:00

1.2 KiB

Security Policy

Reporting a Vulnerability

Report privately through GitHub: Security tab → Report a vulnerability.

Include your macOS version, the Tinycast version and channel, reproduction steps, and the impact. Please don't disclose publicly until it's fixed.

We'll respond as quickly as we can and keep you posted.

Supported Versions

Current stable and beta only. Update (brew upgrade --cask tinycast) before reporting.

Scope

Of particular interest:

  • Accessibility (TCC) — anything that widens what the paste grant enables.
  • Clipboard history — text and images cached on disk; unintended exposure or capture.
  • Network — Tinycast is offline by default and every networked feature is consent-gated. A path that reaches the network without consent, or survives consent being withdrawn, is high severity.
  • Hotkeys — the in-house hotkey stack and the Input Monitoring grant.
  • Signing and distribution — the DMG and Homebrew cask chain.

Out of scope: builds being self-signed rather than notarized (known, see docs/signing.md), and anything needing existing code execution or admin rights on the machine.