Until the first stable release, only the latest published beta receives security fixes. After 1.0, this file will list the supported release branches.
Please use GitHub's Security → Report a vulnerability private reporting flow. If private reporting is not yet enabled, open a minimal issue requesting a private contact channel without disclosing the vulnerability.
Useful reports include the affected HeadBridge version, macOS version, device model/firmware, impact, reproduction conditions, and a proposed mitigation when known. No bounty program is currently offered.
HeadBridge controls local hardware and is not a security boundary. Nevertheless, parser, updater, signing, IPC, and local-data issues are treated as security relevant.