Only the latest published version of each package receives security fixes. Before 1.0 there are no maintenance branches.
os_intents generates code that runs inside your app and registers actions the OS can invoke — including with the app in the background. Things worth reporting privately:
- A way for an invocation to reach a handler the manifest never declared, or to smuggle argument types past the wire-format decoding on either bridge.
- Generated Swift/Kotlin/XML that widens what the OS may invoke beyond what the annotations declared (e.g. an exported component that should not be).
- Anything that makes
os_intents installwrite outside the project it was pointed at. - An error path that leaks handler exception text to the OS surface — the
package deliberately routes exceptions away from Siri's voice
(
OsIntents.unexpectedErrorMessage); a bypass is a bug with privacy consequences.
Please do not open a public issue for a suspected vulnerability. Use GitHub's private reporting instead: Report a vulnerability, or email nugmanovilyas228@gmail.com.
You will get an acknowledgement within 72 hours. Fixes ship as a patch release on every affected package, and the advisory is published after the release — with credit, if you want it.