Security
Report a vulnerability privately
Please use GitHub private vulnerability reporting. Include reproduction steps and the affected version. Do not include private signing keys or sensitive original files.
If reporting is unavailable, open a public issue asking for a private contact without disclosing the vulnerability. This community project has no guaranteed response time.
What you can trust
The original file stays on your device. Receipts bind a SHA-256 hash to the issuer's stated time. A signature does not establish authorship, ownership, independently certified UTC accuracy, or protection against issuer backdating.
Read the full trust model