Security fixes target the latest published DesktopTools release. Older builds may need to update before a fix is available.
Do not open a public issue with exploit details or private user data. Use GitHub's private vulnerability reporting for this repository when available. Include the affected version, impact, reproduction steps, and suggested mitigation, using disposable test data.
If private reporting is unavailable, open a public issue requesting a private maintainer contact without including vulnerability details. Do not attach credentials, private screenshots, recordings, or personal files.
DesktopTools is a local desktop application without an account, telemetry, or cloud service. Capture exclusion and sharing-only blackout are compatibility features, not security boundaries. See download verification for release checksum guidance.
When a fix is published, DesktopTools may show an in-app security update notice. It does not install or restart automatically; users confirm the existing update flow. Publish a GitHub security advisory and release notes as well, because older app versions cannot receive in-app news.