Security fixes are currently provided for the latest published Kori beta. Older development builds may be asked to upgrade before a report is investigated.
Please do not disclose a suspected vulnerability in a public issue.
Email kori.dev@askq.co.nz with the subject
Private security report: Kori. Do not open a public issue containing
security-sensitive details.
Include the Kori, OBS and Windows versions, reproduction steps, the potential impact and any suggested mitigation.
Reports will be acknowledged as soon as practical. A fix and disclosure timeline will be agreed privately after the issue is reproduced.
Official Kori packages are published only through this repository's GitHub Releases page. Beta installers are not yet code-signed. Compare the downloaded ZIP's SHA-256 digest with the checksum shown in its release before installing.