| Version | Security updates |
|---|---|
| 1.0 | Supported |
| Earlier versions | Not supported |
Do not report a suspected vulnerability in a public GitHub issue, release comment, or log excerpt.
This public repository has GitHub private vulnerability reporting enabled. Report a vulnerability from the repository's Security tab using Report a vulnerability.
A useful private report includes:
- the ClassicSpeech and NVDA versions;
- the Windows version;
- clear reproduction steps;
- the expected and actual result;
- the likely impact; and
- only the log excerpts needed to reproduce the issue, with personal data removed.
Do not include passwords, API keys, access tokens, private documents, or unredacted personal data.
Maintainers will assess private reports, work on a fix, and coordinate disclosure before publishing technical details when appropriate.