| Version | Supported |
|---|---|
| 0.2.x | ✅ |
| 0.1.x | ✅ |
Dependabot may report a medium-severity alert for glib in src-tauri/Cargo.lock.
This crate is a transitive Linux-only dependency pulled in by Tauri’s GTK/WebKit stack (gtk 0.18 → glib 0.18). It is not used by the Windows build path, which is the primary distribution target for this project.
Patched versions require glib ≥ 0.20, but the unmaintained GTK3 bindings used by Tauri 2 still require glib 0.18. There is no safe in-repo version bump until Tauri upstream migrates that stack (tauri#12048).
We track Tauri releases for a proper fix and dismiss this alert as an accepted upstream risk until then.
Dependabot may report high-severity alerts for image-size in companion/package-lock.json.
This package is a transitive Metro/Expo bundler dependency. No patched version is recorded for these advisories. npm latest is still 2.0.2, and this repo's lockfile resolves 1.2.1. npm audit fix --force would also try to install Expo SDK 53, which is a breaking change from this project’s SDK 57.
There is no safe in-repo version bump until image-size publishes a patched release. The DoS requires feeding a crafted image buffer to Metro’s image-size parser (dev/bundler path), not the Windows desktop runtime.
Please do not open a public GitHub issue for security vulnerabilities.
Instead, report them through GitHub Security Advisories (preferred) or contact the maintainers privately.
Include:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if you have one)
We will acknowledge receipt within a reasonable timeframe and work on a fix before public disclosure when appropriate.