Preview. PicPrep has not launched yet, and parts of this page are unfinished.

PicPrep Get PicPrep

Security and vulnerability handling

This is how PicPrep handles security problems: how to report one, what happens next, and how fixes reach you. PicPrep is made by one developer, Tal Afek.

Report a security problem

What happens next

  1. Acknowledgement within 3 working days, to the address you gave.
  2. Assessment: I confirm the problem and rate its severity (critical, high, medium or low), using CVSS where it helps, and tell you the rating.
  3. Fix, with these targets from confirmation:

    • critical or actively exploited: as fast as possible, normally within 7 days;
    • high: within 30 days;
    • medium: in the next scheduled security release (at most every 4 weeks);
    • low: in a coming release.

    If a target cannot be met, I tell you why and when to expect it.

  4. Disclosure after the fix: once the fix is released, an advisory is published on this page and shown in the app with the update. It says what was affected, how serious it was, which versions are affected and what to do. In a justified case (for example while a fix in a component such as Chromium is still pending), publication can wait until users can protect themselves.
  5. Credit: you are thanked by name in the advisory, unless you prefer not to be.

There is no paid bug bounty. Reports made in good faith under this policy will not lead to legal action from me.

If the problem is in a component PicPrep uses (for example Electron or Chromium), I also report it to the people who maintain that component.

How fixes reach you

How PicPrep is checked

Advisories

The list of published security advisories is below. Each one names the fixed version.

No security advisories have been published yet.

Machine-readable contact details: security.txt.