NetFlow is a local-first iOS and iPadOS application. Security reports help keep the app, its build configuration, and its documentation trustworthy.
The main branch is the actively maintained line. Older releases are handled on a best-effort basis.
Please do not disclose a suspected vulnerability in a public issue.
Use GitHub's private vulnerability reporting feature from the repository's Security tab when it is available. If private reporting is not enabled, contact the maintainer through the GitHub profile and request a private channel before sharing sensitive details.
Include:
- a clear description of the issue and its impact;
- the affected version, commit, device, and iOS version;
- reproducible steps or a minimal proof of concept; and
- any suggested mitigation.
Do not include passwords, signing certificates, provisioning profiles, private keys, personal data, or production credentials in a report.
Reports are reviewed as time permits. The maintainer may ask for additional details, coordinate a fix, and agree on a disclosure date with the reporter. Please allow time for assessment and remediation before making a report public.
Reports about the NetFlow source code, build scripts, documentation, and repository configuration are in scope. Issues caused solely by Apple platform behavior or unrelated third-party services may need to be reported to their respective maintainers as well.