Skip to content

Security: onemnemo/mnemo

Security

SECURITY.md

Security Policy

Mnemo is a local-first study application, so security and user trust matter.

Reporting a vulnerability

Please do not publicly disclose security vulnerabilities before giving the maintainers a reasonable chance to respond.

To report a vulnerability, contact the project maintainer:

  • GitHub: @torstfugl
  • Repository: onemnemo/mnemo

If a dedicated security email is added later, this file should be updated.

What to include

Please include:

  • a clear description of the issue
  • steps to reproduce
  • affected versions or commits if known
  • potential impact
  • suggested fix if you have one

Scope

Security issues may include, but are not limited to:

  • unsafe file handling
  • arbitrary code execution
  • insecure update behavior
  • data loss or data exposure
  • unsafe AI/model loading behavior
  • unsafe plugin, theme, or extension behavior
  • local privacy issues

Response

Mnemo is maintained as a passion project. Response times may vary, but responsible reports are appreciated.

There aren't any published security advisories