Security
How to report a vulnerability in PrismNext. Please do not open a public GitHub issue for security reports. The repository file SECURITY.md is the same policy.
1. Supported versions
PrismNext is in Early Access. We primarily support the latest released version from GitHub Releases and the in-app updater feed. Please upgrade before reporting an issue that may already be fixed.
2. How to report
Use one of the following:
- GitHub Private Vulnerability Reporting, if enabled on the repository: Security tab → Report a vulnerability.
-
Email
yibocat@yeah.net
with the subject prefix
[PrismNext Security].
3. What to include
Please include as much of the following as you can:
- affected version and platform (macOS, Windows, or Linux);
- the impact, so far as you understand it (for example data exposure or privilege escalation);
- enough information for us to reproduce the issue; and
- whether you plan to disclose publicly, and on what timeline.
We will acknowledge receipt when we can, assess the report, and coordinate a fix and disclosure window. Please give us reasonable time before public disclosure.
4. Scope
PrismNext is local-first and uses bring-your-own-key model credentials. Treat API keys and project files on disk as sensitive.
Reports about third-party model providers, upstream dependencies, or packaged components are welcome when they affect this application’s packaging or defaults. We may redirect a purely upstream issue to the relevant project.