Skip to content

Security: devclinic/evoworks-control

SECURITY.md

Security policy

Supported version

Only the latest tagged beta is supported for security fixes.

Reporting a vulnerability

Please do not open a public issue for a suspected vulnerability involving HID access, installer/update behaviour, local data, or a protocol write path.

Use GitHub's Security > Report a vulnerability private reporting flow for this repository. This sends the report privately to the maintainers so details can be assessed and addressed before public disclosure.

Useful reports include a minimal reproduction, affected version, expected and observed behaviour, and only the smallest redacted diagnostic excerpt needed to understand the issue.

Scope

The project intentionally avoids a driver, service, keyboard hook, telemetry, firmware flashing, and unverified wireless writes. A vulnerability in those boundaries, installer/update flow, device identity checks, local settings/logs, or HID transport is in scope.

There aren't any published security advisories