Security is taken seriously in Porn Fetch. If you discover a security vulnerability, please report it privately so that it can be investigated and fixed before public disclosure.
Porn Fetch is under active development.
| Version | Supported |
|---|---|
| Latest stable release | ✅ Yes |
| Current development version | |
| Older releases | ❌ No |
Users are encouraged to update to the latest available version, especially when an update contains security fixes.
Please do not report security vulnerabilities through public GitHub issues, discussions, pull requests, or other public channels.
Use GitHub's Private Vulnerability Reporting feature:
Security → Report a vulnerability
Please include as much of the following information as possible:
- affected Porn Fetch version;
- affected operating system or platform;
- description of the vulnerability;
- steps required to reproduce it;
- proof-of-concept code or screenshots, if applicable;
- potential security impact;
- suggested mitigation or fix, if known;
- whether you have observed or have evidence of the vulnerability being actively exploited.
Please avoid accessing, modifying, downloading, or deleting data that does not belong to you while investigating a vulnerability.
Security reports may include vulnerabilities affecting:
- the Porn Fetch desktop or command-line application;
- the update mechanism;
- the build or release process;
- authentication or credential handling;
- local data handled by Porn Fetch;
- communication between Porn Fetch and official project infrastructure;
- the official licensing system where a vulnerability could affect Porn Fetch users;
- dependencies where their use creates a vulnerability in Porn Fetch.
General bugs without a security impact should be reported through the normal GitHub issue tracker instead.
After receiving a vulnerability report, I will:
- review and attempt to reproduce the issue;
- determine the affected versions and potential impact;
- develop an appropriate fix or mitigation;
- prepare and test a security update where necessary;
- coordinate disclosure of the vulnerability;
- publish relevant security information after users have had a reasonable opportunity to update.
I aim to acknowledge security reports within 7 calendar days where reasonably possible. As Porn Fetch is maintained primarily by a single developer, investigation and remediation times may vary depending on the complexity and severity of the vulnerability.
Critical vulnerabilities and vulnerabilities known to be actively exploited will be prioritized.
Please give me a reasonable opportunity to investigate and fix a vulnerability before publishing technical details that could put users at risk.
If you intend to publicly disclose the vulnerability, please mention this in your report so that disclosure and remediation can be coordinated.
After a fix is available, relevant information may be published through a GitHub Security Advisory, release notes, or other project communication channels.
Security updates will be distributed through official Porn Fetch release and update channels.
Users should obtain Porn Fetch and its updates only from official project sources.
Good-faith security research and responsible vulnerability reporting are appreciated.
Please:
- limit testing to what is necessary to demonstrate the vulnerability;
- do not intentionally disrupt project infrastructure or services;
- do not perform denial-of-service testing;
- do not access data belonging to other users;
- do not use discovered vulnerabilities for financial gain, unauthorized access, or other malicious purposes;
- keep vulnerability details private while a fix is being prepared.
Thank you for helping keep Porn Fetch and its users secure.