Skip to content

Security: ripstop-dev/ripstop-swift

Security

SECURITY.md

Security policy

Reporting a vulnerability

Please do not open a public issue for security problems.

Use GitHub's private vulnerability reporting on the affected repository (Security → Report a vulnerability), or email security@ripstop.dev.

We aim to acknowledge reports within 48 hours and to ship a fix or mitigation within 14 days for confirmed issues.

Scope

  • Ripstop SDKs (ripstop-flutter, ripstop-swift, ripstop-kotlin, ripstop-react-native, ripstop-web)
  • Ripstop services (ripstop.dev, app.ripstop.dev, api.ripstop.dev, cfg.ripstop.dev)

What we care about most

  • Anything that lets an unauthorized party alter a served config (a decision an app obeys must be tamper-proof)
  • Signature verification bypasses in SDKs
  • Authentication or authorization flaws in the dashboard or management API

Out of scope

  • Denial of service via traffic volume
  • Reports from automated scanners without a demonstrated impact

Thank you for helping keep mobile releases safe to stop.

There aren't any published security advisories