Doc location
SECURITY.md (repo root)
What kind of change?
Missing section
What’s wrong or missing?
The repo has no standard security policy file. Users and researchers do not know how to report vulnerabilities privately or what is in scope (local capture, OAuth tokens, installer, etc.).
Suggested fix (optional)
Add a short SECURITY.md:
- Supported versions (e.g. latest release + main).
- How to report (private email or GitHub Security Advisories — pick one).
- What to include (version, OS, steps, impact).
- Brief scope note: local-first app, VRoid OAuth in userData, no mandatory cloud.
- Expected response time (best-effort is fine).
Link from README footer or Contributing if appropriate.
Checklist
Doc location
SECURITY.md(repo root)What kind of change?
Missing section
What’s wrong or missing?
The repo has no standard security policy file. Users and researchers do not know how to report vulnerabilities privately or what is in scope (local capture, OAuth tokens, installer, etc.).
Suggested fix (optional)
Add a short
SECURITY.md:Link from README footer or Contributing if appropriate.
Checklist