Skip to content

Security: mcographics/WorkDaywithGod

SECURITY.md

Security Policy

Thank you for helping keep Work Day with God safe for everyone.

Supported versions

Security updates are currently provided for the latest published version of Work Day with God.

Version Supported
Latest release Yes
Older releases No

Before reporting a vulnerability, please confirm that the issue still affects the latest release.

Reporting a vulnerability

Please do not disclose security vulnerabilities through public GitHub Issues, Discussions, pull requests, or social media.

Use GitHub's private vulnerability-reporting form:

Report a vulnerability privately

Please include:

  • The affected Work Day with God version
  • Your operating system, device model where applicable, and operating-system version
  • A clear description of the vulnerability
  • Detailed steps to reproduce the issue
  • The potential security impact
  • Relevant logs, screenshots, or proof-of-concept material
  • A suggested correction, if known

Do not include passwords, access tokens, private keys, personal information, or data belonging to another person.

What to expect

After receiving a report, the project will aim to:

  • Acknowledge the report within seven days
  • Investigate and validate the reported issue
  • Keep the reporter informed when practical
  • Develop and test an appropriate correction
  • Publish an updated release when necessary
  • Credit the reporter when requested and appropriate

Response and correction times depend on the severity and complexity of the vulnerability. Reports that cannot be reproduced or do not present a security risk may be declined with an explanation.

Responsible disclosure

Please allow reasonable time for investigation and correction before publishing vulnerability details.

Security researchers are asked to:

  • Test only systems and data they own or have permission to use
  • Avoid accessing or modifying another person's data
  • Avoid privacy violations, service disruption, or destructive testing
  • Stop testing if sensitive information is encountered
  • Provide enough information to reproduce the issue safely
  • Keep vulnerability details private until a correction is available

Scope

Appropriate security reports include:

  • Arbitrary code execution
  • Unsafe Electron or preload behavior
  • Unauthorized local file access or path traversal
  • Exposure of locally stored application data
  • Insecure navigation or external-link handling
  • Installer security issues
  • Notification or reminder abuse with a security impact
  • Vulnerabilities in bundled dependencies
  • Circumvention of application security boundaries

General software bugs, feature requests, devotional-content corrections, and usability feedback should be submitted through regular GitHub Issues.

Privacy

Work Day with God is an offline-first application. Settings, favourites, reading history, completion records, and reminder information are stored locally on the user's computer or mobile device.

If a vulnerability report contains personal or sensitive information, it will be handled only as needed to investigate and resolve the report.

Bug bounty

Work Day with God is a completely free application and does not currently operate a paid bug-bounty program. Responsible security reports are sincerely appreciated.

There aren't any published security advisories