Add security policy and issue/PR templates - #24
Merged
Conversation
Points to GitHub's private vulnerability reporting (enabled on the repo alongside secret scanning + push protection, all free on a public repo) instead of a personal email, since there's no team/ infra to route reports to. Scope section is upfront about this being a local-network-only app -- exploiting anything here needs an attacker already on the same Wi-Fi -- and points at the specific network/logging files most relevant to a review. JA/ZH carry the same unreviewed-machine-translation disclaimer as the other translated docs; EN/FR are the authoritative pair. Linked from README.md/README_FR.md next to the existing Contributing section (JA/ZH READMEs left as-is for now).
Bug report form asks for device/Android version/tracking tier/network target upfront (behavior here is highly device- and config-dependent) and points at the in-app log export instead of relying on memory. Feature request form reminds contributors of the discuss-before-PR convention from CONTRIBUTING.md. config.yml disables blank issues and redirects security reports to private vulnerability reporting instead. PR template checks CLA agreement, real-device testing, and the revue-technique sync convention.
3 tasks
guyiome
added a commit
that referenced
this pull request
Sep 2, 2026
Patch release over v0.3.0: the new artist logo (#30), the camera preview/overlay freeze fix on in-app language change (#26), the security policy and issue templates (#24), and two dependency batches (#25, #31). Bumping versionName is not cosmetic here, it's required before tagging: the in-app update checker compares BuildConfig.VERSION_NAME against the latest GitHub release tag, so tagging v0.3.1 while the build still reported 0.3.0 would show a permanent, unclearable "update available" badge to users already running the newest build. No README sync this time, unlike the v0.3.0 preparation: that one tracked newly added features, whereas everything since is fixes plus the logo. Checked that no tracked doc still credits the previous placeholder logo. Verified the built APK actually reports the new version (aapt2 dump badging: versionCode='4' versionName='0.3.1') rather than assuming the edit took effect. Unit tests, debug build and lint all pass.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
docs/SECURITY.md(+ FR/JA/ZH) -- points to GitHub's private vulnerability reporting rather than a personal email; scope section explains this is a local-network-only app..github/ISSUE_TEMPLATE/(bug report form, feature request form, config disabling blank issues + redirecting security reports)..github/PULL_REQUEST_TEMPLATE.md.Test plan