Please do not open a public issue for security problems.
Use GitHub's private vulnerability reporting on the affected repository (Security → Report a vulnerability), or email security@ripstop.dev.
We aim to acknowledge reports within 48 hours and to ship a fix or mitigation within 14 days for confirmed issues.
- Ripstop SDKs (
ripstop-flutter,ripstop-swift,ripstop-kotlin,ripstop-react-native,ripstop-web) - Ripstop services (
ripstop.dev,app.ripstop.dev,api.ripstop.dev,cfg.ripstop.dev)
- Anything that lets an unauthorized party alter a served config (a decision an app obeys must be tamper-proof)
- Signature verification bypasses in SDKs
- Authentication or authorization flaws in the dashboard or management API
- Denial of service via traffic volume
- Reports from automated scanners without a demonstrated impact
Thank you for helping keep mobile releases safe to stop.