PicChronoImporter reads user-selected media and writes imported copies, so reports involving data loss, unintended overwrite, path traversal, permission scope, or exposure of file metadata are treated as security-sensitive.
There is no stable public binary release yet. Security fixes target the current
main branch. Historical commits and locally built binaries are not supported.
Use GitHub private vulnerability reporting from this repository's Security tab when it is available. Do not open a public issue with exploit details, private paths, volume identifiers, media metadata, or user files.
If private vulnerability reporting is temporarily unavailable, open a minimal Issue asking the maintainer to provide a private reporting channel. Do not include vulnerability details or sensitive data in that Issue.
Please include:
- the affected commit or version
- the macOS and Xcode versions used
- a concise impact assessment and reproduction steps
- whether source or destination data can be changed or disclosed
- a minimal synthetic test case when possible
Never attach personal photos, videos, a populated real-media manifest, access
tokens, or other private data. Replace paths and identifiers with synthetic
values such as /Users/example/....
The maintainer will acknowledge a report when practical, validate the issue, and coordinate a fix and disclosure timeline through the private report. No formal response-time SLA is currently offered.