Skip to content

Security: Alexism1442/Curio

Security

SECURITY.md

Security Policy

Supported versions

Curio is distributed as a signed APK from GitHub Releases. Only the latest published release receives security fixes — always update to the newest version.

Reporting a vulnerability

Please do not open a public issue for a security vulnerability until it has been addressed.

  • Preferred: use GitHub's private vulnerability reporting (repo Security → Report a vulnerability), if it is enabled on this repository.
  • Alternative: open a GitHub Issue with [security] in the title, and let the maintainer triage privately from there.

Please include:

  • The app version (Profile → Support & diagnostics → Version) and Android version.
  • A clear description of the issue and, if possible, steps to reproduce.
  • Whether the issue affects stored data (the app is fully offline — captures live only on-device and in backups).

Scope

Curio is an offline-first app: there is no server, no accounts, and no cloud sync. Issues with the bundled topic content (factual errors in descriptions) belong in the issues tracker, not here.

There aren't any published security advisories