Skip to content

Security: upzare/Waffy

Security

SECURITY.md

Security Policy

Supported versions

Security fixes are provided for the latest release on the default branch.

Version Supported
Latest Yes
Older No

Reporting a vulnerability

If you discover a security vulnerability in Waffy, please report it responsibly.

Please do not open a public GitHub issue for security vulnerabilities.

Instead, email support@waffy.io with:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact
  • Any suggested fix, if you have one

We will acknowledge your report within a reasonable timeframe and work with you to understand and address the issue. We ask that you allow us time to investigate and release a fix before public disclosure.

Scope

This policy covers the Waffy browser extension source code in this repository. It does not cover third-party AI provider APIs or websites you automate with Waffy.

Safe use reminders

  • API keys are stored locally in Chrome extension storage. Do not share your profile or storage exports.
  • Only install Waffy from this repository or official Waffy distribution channels.
  • Review permissions requested by the extension before use.

There aren't any published security advisories