Thank you for helping keep Work Day with God safe for everyone.
Security updates are currently provided for the latest published version of Work Day with God.
| Version | Supported |
|---|---|
| Latest release | Yes |
| Older releases | No |
Before reporting a vulnerability, please confirm that the issue still affects the latest release.
Please do not disclose security vulnerabilities through public GitHub Issues, Discussions, pull requests, or social media.
Use GitHub's private vulnerability-reporting form:
Report a vulnerability privately
Please include:
- The affected Work Day with God version
- Your operating system, device model where applicable, and operating-system version
- A clear description of the vulnerability
- Detailed steps to reproduce the issue
- The potential security impact
- Relevant logs, screenshots, or proof-of-concept material
- A suggested correction, if known
Do not include passwords, access tokens, private keys, personal information, or data belonging to another person.
After receiving a report, the project will aim to:
- Acknowledge the report within seven days
- Investigate and validate the reported issue
- Keep the reporter informed when practical
- Develop and test an appropriate correction
- Publish an updated release when necessary
- Credit the reporter when requested and appropriate
Response and correction times depend on the severity and complexity of the vulnerability. Reports that cannot be reproduced or do not present a security risk may be declined with an explanation.
Please allow reasonable time for investigation and correction before publishing vulnerability details.
Security researchers are asked to:
- Test only systems and data they own or have permission to use
- Avoid accessing or modifying another person's data
- Avoid privacy violations, service disruption, or destructive testing
- Stop testing if sensitive information is encountered
- Provide enough information to reproduce the issue safely
- Keep vulnerability details private until a correction is available
Appropriate security reports include:
- Arbitrary code execution
- Unsafe Electron or preload behavior
- Unauthorized local file access or path traversal
- Exposure of locally stored application data
- Insecure navigation or external-link handling
- Installer security issues
- Notification or reminder abuse with a security impact
- Vulnerabilities in bundled dependencies
- Circumvention of application security boundaries
General software bugs, feature requests, devotional-content corrections, and usability feedback should be submitted through regular GitHub Issues.
Work Day with God is an offline-first application. Settings, favourites, reading history, completion records, and reminder information are stored locally on the user's computer or mobile device.
If a vulnerability report contains personal or sensitive information, it will be handled only as needed to investigate and resolve the report.
Work Day with God is a completely free application and does not currently operate a paid bug-bounty program. Responsible security reports are sincerely appreciated.