Security fixes target the current main branch until the project starts publishing stable releases.
Report vulnerabilities privately to the maintainer before opening a public issue. Include:
- Affected commit or release.
- Host OS and Android version.
- Reproduction steps or proof of concept.
- Impact and any known mitigations.
Relevant issues include unintended input injection, unsafe handling of device identifiers, privilege escalation in input backends, and leakage of clipboard or device data.
Do not include secrets, private device identifiers, or personal data in public reports.