Skip to content

Security: m1roxx/os_intents

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest published version of each package receives security fixes. Before 1.0 there are no maintenance branches.

What counts as a security issue here

os_intents generates code that runs inside your app and registers actions the OS can invoke — including with the app in the background. Things worth reporting privately:

  • A way for an invocation to reach a handler the manifest never declared, or to smuggle argument types past the wire-format decoding on either bridge.
  • Generated Swift/Kotlin/XML that widens what the OS may invoke beyond what the annotations declared (e.g. an exported component that should not be).
  • Anything that makes os_intents install write outside the project it was pointed at.
  • An error path that leaks handler exception text to the OS surface — the package deliberately routes exceptions away from Siri's voice (OsIntents.unexpectedErrorMessage); a bypass is a bug with privacy consequences.

Reporting a vulnerability

Please do not open a public issue for a suspected vulnerability. Use GitHub's private reporting instead: Report a vulnerability, or email nugmanovilyas228@gmail.com.

You will get an acknowledgement within 72 hours. Fixes ship as a patch release on every affected package, and the advisory is published after the release — with credit, if you want it.

There aren't any published security advisories