Security and vulnerability handling
This is how PicPrep handles security problems: how to report one, what happens next, and how fixes reach you. PicPrep is made by one developer, [Full name].
Report a security problem
- Email [email protected]. Write in English if you can.
- Or, inside PicPrep, use Help → Report a security problem. It is sent privately and is never posted publicly. Include your email address in the description if you want a reply.
- Please include: the PicPrep version (Help → About), your operating system, what an attacker could do, and the steps or a file that shows it. If it involves a crafted photo or project file, attach it.
- Please do not post the details publicly, or test against other people's computers, before a fix is released.
What happens next
- Acknowledgement within 3 working days, to the address you gave.
- Assessment: I confirm the problem and rate its severity (critical, high, medium or low), using CVSS where it helps, and tell you the rating.
Fix, with these targets from confirmation:
- critical or actively exploited: as fast as possible, normally within 7 days;
- high: within 30 days;
- medium: in the next scheduled security release (at most every 4 weeks);
- low: in a coming release.
If a target cannot be met, I tell you why and when to expect it.
- Disclosure after the fix: once the fix is released, an advisory is published on this page and shown in the app with the update. It says what was affected, how serious it was, which versions are affected and what to do. In a justified case (for example while a fix in a component such as Chromium is still pending), publication can wait until users can protect themselves.
- Credit: you are thanked by name in the advisory, unless you prefer not to be.
There is no paid bug bounty. Reports made in good faith under this policy will not lead to legal action from me.
If the problem is in a component PicPrep uses (for example Electron or Chromium), I also report it to the people who maintain that component.
How fixes reach you
- Free for every copy. Security updates are free for every copy, whether the subscription is active, has ended, or is still in trial, until at least five years after purchase. Settings → Licence shows the date for your copy.
- Installed automatically by default. Security releases install by default. You can turn automatic updates off in Settings, or postpone a single update. On Linux, PicPrep shows a notice with a download link instead.
- Marked as security. Each security release is marked as one in the update feed, with an advisory that says what it fixes. Where feasible, it is released separately from new features.
- Delivered securely. Updates are delivered over HTTPS from private storage, through links that expire after a few minutes. macOS builds are signed and notarised, and macOS refuses an update without the same signature.
- Regular and urgent releases. Fixes for the components inside PicPrep (Electron, which includes Chromium) are released at least every 4 weeks when there are any. An actively exploited vulnerability is fixed and released at once.
How PicPrep is checked
- One outside runtime component. PicPrep uses one outside runtime component, Electron. Its updates are tracked automatically and applied as soon as they are released.
- A list of components for every release. Each release comes with a software bill of materials (SBOM, in CycloneDX format) that lists its components and versions. It is kept for at least ten years and provided on request.
- Tested on every system. Every change runs the automated tests. Every release runs them on macOS, Windows and Linux.
- Reported to the authorities. An actively exploited vulnerability is reported to the EU authorities as the Cyber Resilience Act requires (Article 14), and users are told what to do.
Advisories
The list of published security advisories is below. Each one names the fixed version.
No security advisories have been published yet.
Machine-readable contact details: security.txt.