Reports are welcome for repository-controlled TextbookLens desktop code, including credential handling, local-data ownership, backup/restore, deletion, provider consent, redaction, and dependency/build supply chain issues.
This checkout has no configured repository URL, security contact, email address, bug-bounty program, SLA, signing key, update channel, or private reporting endpoint. Do not send a report to an invented address or publish sensitive details in a public issue.
If this repository is later hosted on GitHub with Security Advisories enabled, use that repository’s private Report a vulnerability mechanism. Until a maintainer configures a private channel, ask the maintainer for one before sharing sensitive material.
Provide a minimal, redacted reproduction: affected revision/build, Windows and application version, non-sensitive steps, expected/actual behavior, impact, and a safe proof. Do not include API keys, credential identifiers, textbook text/images, prompts, answers, notes, teaching instructions, provider raw bodies, remote-resource IDs, backups, database files, logs, diagnostics, or private absolute paths. Use self-made synthetic data when a sample is necessary.
The project makes no promise about response/disclosure timing, CVE handling, encrypted mail, signatures, automatic updates, or rewards.