| Version | Supported |
|---|---|
| 0.2.x | ✅ |
| 0.1.x | ✅ |
Dependabot may report a medium-severity alert for glib in src-tauri/Cargo.lock.
This crate is a transitive Linux-only dependency pulled in by Tauri’s GTK/WebKit stack (gtk 0.18 → glib 0.18). It is not used by the Windows build path, which is the primary distribution target for this project.
Patched versions require glib ≥ 0.20, but the unmaintained GTK3 bindings used by Tauri 2 still require glib 0.18. There is no safe in-repo version bump until Tauri upstream migrates that stack (tauri#12048).
We track Tauri releases for a proper fix and dismiss this alert as an accepted upstream risk until then.
Dependabot may report high-severity alerts for these packages in companion/package-lock.json.
Both are transitive Expo/Metro tooling dependencies. No patched npm release is published yet (braces latest is still 3.0.3; node-forge latest is still 1.4.0). npm audit fix --force would try to install Expo SDK 44, which is a breaking downgrade from this project’s SDK 57.
There is no safe in-repo version bump until the maintainers publish patched releases (or Expo pins them). Impact is limited to the companion bundler/dev path, not the Windows desktop runtime.
Please do not open a public GitHub issue for security vulnerabilities.
Instead, report them through GitHub Security Advisories (preferred) or contact the maintainers privately.
Include:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if you have one)
We will acknowledge receipt within a reasonable timeframe and work on a fix before public disclosure when appropriate.