Skip to content

Security: trssharp/classicspeech-nvda

SECURITY.md

Security policy

Supported versions

Version Security updates
1.0 Supported
Earlier versions Not supported

Reporting a vulnerability

Do not report a suspected vulnerability in a public GitHub issue, release comment, or log excerpt.

This public repository has GitHub private vulnerability reporting enabled. Report a vulnerability from the repository's Security tab using Report a vulnerability.

A useful private report includes:

  1. the ClassicSpeech and NVDA versions;
  2. the Windows version;
  3. clear reproduction steps;
  4. the expected and actual result;
  5. the likely impact; and
  6. only the log excerpts needed to reproduce the issue, with personal data removed.

Do not include passwords, API keys, access tokens, private documents, or unredacted personal data.

Response approach

Maintainers will assess private reports, work on a fix, and coordinate disclosure before publishing technical details when appropriate.

There aren't any published security advisories