Skip to content

Security: DlamondEyes/ShelfReader

Security

SECURITY.md

Security Policy

Supported version

Only the latest commit on the default branch is currently supported. ShelfReader is a Beta prototype and has not received a production security audit.

Reporting

Do not include API keys, private documents, signing assets, device identifiers, or extracted book text in a public issue. Use GitHub's private vulnerability reporting feature for security or privacy problems when it is available on the repository.

Credential handling

The app stores an optional DeepSeek API Key in iOS Keychain. The repository must never contain a real provider key. If a credential is accidentally committed, revoke it before reporting the incident.

There aren't any published security advisories