Security fixes are provided for the latest release on the default branch.
| Version | Supported |
|---|---|
| 1.x | Yes |
| Earlier prototypes | No |
Please use GitHub's private vulnerability reporting for this repository. Open the Security tab, choose Advisories, then Report a vulnerability.
Do not open a public issue for vulnerabilities involving microphone capture, Accessibility insertion, Input Monitoring, keychain storage, local history, model downloads, or accidental network transmission.
Include reproduction steps, affected macOS version, expected impact, and a minimal synthetic example. Do not include real prompt history, private audio, API keys, or other people's data.
You should receive an initial response within seven days. Please allow time to investigate and prepare a coordinated fix before public disclosure.