Security: egdels/makeacopy

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

We take security seriously and appreciate your efforts to responsibly disclose any security vulnerabilities you discover.

How to Report

Please do NOT open a public GitHub issue for security vulnerabilities. Instead, please report security vulnerabilities to the project maintainers privately.

  1. Use GitHub's Security Advisory Form

  2. Or contact the maintainers directly

    • Send an email describing the vulnerability with details about:
      • The type of vulnerability
      • Location in the code (if applicable)
      • Potential impact
      • Any suggested fixes or workarounds

What to Include

Please provide as much information as possible to help us understand and assess the vulnerability:

  • Description - A clear description of the vulnerability
  • Affected Version(s) - Which version(s) of MakeACopy are affected
  • Steps to Reproduce - How to reproduce the issue (if applicable)
  • Potential Impact - What could an attacker do with this vulnerability?
  • Suggested Fix - If you have a suggestion for fixing the issue (optional)
  • Your Contact Information - How we can reach you if we need more details

Security Response Timeline

We will make our best effort to:

  1. Acknowledge receipt - Respond within 3-5 business days to confirm we received your report
  2. Investigate - Work to understand and reproduce the issue
  3. Develop a fix - Create and test a patch
  4. Coordinate disclosure - Work with you on a responsible disclosure timeline
  5. Release patch - Issue a security update and publicly disclose the vulnerability

Depending on the complexity and severity of the vulnerability, this process may take anywhere from a few days to a few weeks.

Disclosure Policy

We follow a responsible disclosure process:

  1. After receiving your report, we will work to verify and understand the vulnerability
  2. We will attempt to fix the issue and release a patch
  3. We will coordinate with you on the timing of public disclosure
  4. We will credit you in the security advisory if you wish (with your permission)
  5. We aim to have a patch available before public disclosure, when possible

Supported Versions

VersionStatusSecurity Updates
3.xLatest✅ Yes
2.xOlder⚠️ Case by case
1.xOutdated❌ No

We recommend users keep their application up to date with the latest version to ensure they have the latest security patches.

Security Considerations

Offline-First Architecture

MakeACopy is designed to work completely offline. This design choice significantly reduces certain classes of security risks:

  • ✅ No network requests to untrusted servers
  • ✅ No cloud storage of user data
  • ✅ No tracking or analytics
  • ✅ No third-party API dependencies

However, other security considerations remain important:

  • Input validation for document processing
  • Safe handling of OCR models and image processing
  • Secure storage of any cached data
  • Safe handling of file I/O operations

Dependencies

We carefully select and maintain our dependencies:

  • ONNX Runtime - ML inference engine for document detection
  • OpenCV - Image processing library
  • Tesseract/Leptonica - OCR engines

All dependencies are regularly updated to patch known vulnerabilities. We use tools like:

  • Gradle dependency scanning
  • GitHub's Dependabot for monitoring CVEs
  • Regular security audits

Code Review

All code changes, including security fixes, go through:

  • Code review by maintainers
  • Automated testing (unit and instrumented tests)
  • Lint checks and code quality analysis
  • Compatibility testing on multiple Android versions

Android Security Features

MakeACopy leverages Android's built-in security features:

  • Sandboxing - Each app instance is isolated from others
  • Permission System - Users must grant permissions for camera, storage, etc.
  • SELinux - Android's mandatory access control framework
  • Code Signing - All releases are cryptographically signed

Build Reproducibility

Official releases are built to be reproducible, allowing community members to verify builds:

  • Fixed tool versions (JDK, NDK, CMake)
  • Deterministic build process
  • Published build scripts and documentation
  • APK signature verification available

APK Verification

All official releases are cryptographically signed. You can verify the authenticity of APKs:

Upload Key (used for GitHub releases, F-Droid, and sideload APKs):

SHA-256: AE:32:2D:3F:B7:1A:FE:21:DF:47:27:E3:7A:5C:68:03:51:1D:5A:2F:E1:FC:31:35:43:0C:EE:06:99:FA:1B:34

Google Play App Signing Key:

  • Used for Play Store releases only

Staying Informed

To stay informed about security updates:

  • ⭐ Watch the GitHub repository for release notifications
  • 📧 Subscribe to release announcements
  • 🔔 Enable notifications for security advisories

Scope

This security policy covers:

  • The MakeACopy application code
  • Official releases (F-Droid, Google Play, GitHub Releases)
  • The project documentation and build infrastructure

This security policy does not cover:

  • Third-party forks or modified versions
  • Older versions beyond the supported versions listed above
  • Dependencies maintained by third parties (though we will help coordinate fixes)

Questions or Concerns?

If you have questions about this security policy or security in general, feel free to open a private security advisory or discussion in the repository.


Thank you for helping keep MakeACopy secure!

We appreciate the security research community and responsible disclosure practices that help make our project safer for all users.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Security: egdels/makeacopy

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

We take security seriously and appreciate your efforts to responsibly disclose any security vulnerabilities you discover.

How to Report

Please do NOT open a public GitHub issue for security vulnerabilities. Instead, please report security vulnerabilities to the project maintainers privately.

  1. Use GitHub's Security Advisory Form

  2. Or contact the maintainers directly

    • Send an email describing the vulnerability with details about:
      • The type of vulnerability
      • Location in the code (if applicable)
      • Potential impact
      • Any suggested fixes or workarounds

What to Include

Please provide as much information as possible to help us understand and assess the vulnerability:

  • Description - A clear description of the vulnerability
  • Affected Version(s) - Which version(s) of MakeACopy are affected
  • Steps to Reproduce - How to reproduce the issue (if applicable)
  • Potential Impact - What could an attacker do with this vulnerability?
  • Suggested Fix - If you have a suggestion for fixing the issue (optional)
  • Your Contact Information - How we can reach you if we need more details

Security Response Timeline

We will make our best effort to:

  1. Acknowledge receipt - Respond within 3-5 business days to confirm we received your report
  2. Investigate - Work to understand and reproduce the issue
  3. Develop a fix - Create and test a patch
  4. Coordinate disclosure - Work with you on a responsible disclosure timeline
  5. Release patch - Issue a security update and publicly disclose the vulnerability

Depending on the complexity and severity of the vulnerability, this process may take anywhere from a few days to a few weeks.

Disclosure Policy

We follow a responsible disclosure process:

  1. After receiving your report, we will work to verify and understand the vulnerability
  2. We will attempt to fix the issue and release a patch
  3. We will coordinate with you on the timing of public disclosure
  4. We will credit you in the security advisory if you wish (with your permission)
  5. We aim to have a patch available before public disclosure, when possible

Supported Versions

VersionStatusSecurity Updates
3.xLatest✅ Yes
2.xOlder⚠️ Case by case
1.xOutdated❌ No

We recommend users keep their application up to date with the latest version to ensure they have the latest security patches.

Security Considerations

Offline-First Architecture

MakeACopy is designed to work completely offline. This design choice significantly reduces certain classes of security risks:

  • ✅ No network requests to untrusted servers
  • ✅ No cloud storage of user data
  • ✅ No tracking or analytics
  • ✅ No third-party API dependencies

However, other security considerations remain important:

  • Input validation for document processing
  • Safe handling of OCR models and image processing
  • Secure storage of any cached data
  • Safe handling of file I/O operations

Dependencies

We carefully select and maintain our dependencies:

  • ONNX Runtime - ML inference engine for document detection
  • OpenCV - Image processing library
  • Tesseract/Leptonica - OCR engines

All dependencies are regularly updated to patch known vulnerabilities. We use tools like:

  • Gradle dependency scanning
  • GitHub's Dependabot for monitoring CVEs
  • Regular security audits

Code Review

All code changes, including security fixes, go through:

  • Code review by maintainers
  • Automated testing (unit and instrumented tests)
  • Lint checks and code quality analysis
  • Compatibility testing on multiple Android versions

Android Security Features

MakeACopy leverages Android's built-in security features:

  • Sandboxing - Each app instance is isolated from others
  • Permission System - Users must grant permissions for camera, storage, etc.
  • SELinux - Android's mandatory access control framework
  • Code Signing - All releases are cryptographically signed

Build Reproducibility

Official releases are built to be reproducible, allowing community members to verify builds:

  • Fixed tool versions (JDK, NDK, CMake)
  • Deterministic build process
  • Published build scripts and documentation
  • APK signature verification available

APK Verification

All official releases are cryptographically signed. You can verify the authenticity of APKs:

Upload Key (used for GitHub releases, F-Droid, and sideload APKs):

SHA-256: AE:32:2D:3F:B7:1A:FE:21:DF:47:27:E3:7A:5C:68:03:51:1D:5A:2F:E1:FC:31:35:43:0C:EE:06:99:FA:1B:34

Google Play App Signing Key:

  • Used for Play Store releases only

Staying Informed

To stay informed about security updates:

  • ⭐ Watch the GitHub repository for release notifications
  • 📧 Subscribe to release announcements
  • 🔔 Enable notifications for security advisories

Scope

This security policy covers:

  • The MakeACopy application code
  • Official releases (F-Droid, Google Play, GitHub Releases)
  • The project documentation and build infrastructure

This security policy does not cover:

  • Third-party forks or modified versions
  • Older versions beyond the supported versions listed above
  • Dependencies maintained by third parties (though we will help coordinate fixes)

Questions or Concerns?

If you have questions about this security policy or security in general, feel free to open a private security advisory or discussion in the repository.


Thank you for helping keep MakeACopy secure!

We appreciate the security research community and responsible disclosure practices that help make our project safer for all users.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: egdels/makeacopy

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

We take security seriously and appreciate your efforts to responsibly disclose any security vulnerabilities you discover.

How to Report

Please do NOT open a public GitHub issue for security vulnerabilities. Instead, please report security vulnerabilities to the project maintainers privately.

  1. Use GitHub's Security Advisory Form

  2. Or contact the maintainers directly

    • Send an email describing the vulnerability with details about:
      • The type of vulnerability
      • Location in the code (if applicable)
      • Potential impact
      • Any suggested fixes or workarounds

What to Include

Please provide as much information as possible to help us understand and assess the vulnerability:

  • Description - A clear description of the vulnerability
  • Affected Version(s) - Which version(s) of MakeACopy are affected
  • Steps to Reproduce - How to reproduce the issue (if applicable)
  • Potential Impact - What could an attacker do with this vulnerability?
  • Suggested Fix - If you have a suggestion for fixing the issue (optional)
  • Your Contact Information - How we can reach you if we need more details

Security Response Timeline

We will make our best effort to:

  1. Acknowledge receipt - Respond within 3-5 business days to confirm we received your report
  2. Investigate - Work to understand and reproduce the issue
  3. Develop a fix - Create and test a patch
  4. Coordinate disclosure - Work with you on a responsible disclosure timeline
  5. Release patch - Issue a security update and publicly disclose the vulnerability

Depending on the complexity and severity of the vulnerability, this process may take anywhere from a few days to a few weeks.

Disclosure Policy

We follow a responsible disclosure process:

  1. After receiving your report, we will work to verify and understand the vulnerability
  2. We will attempt to fix the issue and release a patch
  3. We will coordinate with you on the timing of public disclosure
  4. We will credit you in the security advisory if you wish (with your permission)
  5. We aim to have a patch available before public disclosure, when possible

Supported Versions

VersionStatusSecurity Updates
3.xLatest✅ Yes
2.xOlder⚠️ Case by case
1.xOutdated❌ No

We recommend users keep their application up to date with the latest version to ensure they have the latest security patches.

Security Considerations

Offline-First Architecture

MakeACopy is designed to work completely offline. This design choice significantly reduces certain classes of security risks:

  • ✅ No network requests to untrusted servers
  • ✅ No cloud storage of user data
  • ✅ No tracking or analytics
  • ✅ No third-party API dependencies

However, other security considerations remain important:

  • Input validation for document processing
  • Safe handling of OCR models and image processing
  • Secure storage of any cached data
  • Safe handling of file I/O operations

Dependencies

We carefully select and maintain our dependencies:

  • ONNX Runtime - ML inference engine for document detection
  • OpenCV - Image processing library
  • Tesseract/Leptonica - OCR engines

All dependencies are regularly updated to patch known vulnerabilities. We use tools like:

  • Gradle dependency scanning
  • GitHub's Dependabot for monitoring CVEs
  • Regular security audits

Code Review

All code changes, including security fixes, go through:

  • Code review by maintainers
  • Automated testing (unit and instrumented tests)
  • Lint checks and code quality analysis
  • Compatibility testing on multiple Android versions

Android Security Features

MakeACopy leverages Android's built-in security features:

  • Sandboxing - Each app instance is isolated from others
  • Permission System - Users must grant permissions for camera, storage, etc.
  • SELinux - Android's mandatory access control framework
  • Code Signing - All releases are cryptographically signed

Build Reproducibility

Official releases are built to be reproducible, allowing community members to verify builds:

  • Fixed tool versions (JDK, NDK, CMake)
  • Deterministic build process
  • Published build scripts and documentation
  • APK signature verification available

APK Verification

All official releases are cryptographically signed. You can verify the authenticity of APKs:

Upload Key (used for GitHub releases, F-Droid, and sideload APKs):

SHA-256: AE:32:2D:3F:B7:1A:FE:21:DF:47:27:E3:7A:5C:68:03:51:1D:5A:2F:E1:FC:31:35:43:0C:EE:06:99:FA:1B:34

Google Play App Signing Key:

  • Used for Play Store releases only

Staying Informed

To stay informed about security updates:

  • ⭐ Watch the GitHub repository for release notifications
  • 📧 Subscribe to release announcements
  • 🔔 Enable notifications for security advisories

Scope

This security policy covers:

  • The MakeACopy application code
  • Official releases (F-Droid, Google Play, GitHub Releases)
  • The project documentation and build infrastructure

This security policy does not cover:

  • Third-party forks or modified versions
  • Older versions beyond the supported versions listed above
  • Dependencies maintained by third parties (though we will help coordinate fixes)

Questions or Concerns?

If you have questions about this security policy or security in general, feel free to open a private security advisory or discussion in the repository.


Thank you for helping keep MakeACopy secure!

We appreciate the security research community and responsible disclosure practices that help make our project safer for all users.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: egdels/makeacopy

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

We take security seriously and appreciate your efforts to responsibly disclose any security vulnerabilities you discover.

How to Report

Please do NOT open a public GitHub issue for security vulnerabilities. Instead, please report security vulnerabilities to the project maintainers privately.

  1. Use GitHub's Security Advisory Form

  2. Or contact the maintainers directly

    • Send an email describing the vulnerability with details about:
      • The type of vulnerability
      • Location in the code (if applicable)
      • Potential impact
      • Any suggested fixes or workarounds

What to Include

Please provide as much information as possible to help us understand and assess the vulnerability:

  • Description - A clear description of the vulnerability
  • Affected Version(s) - Which version(s) of MakeACopy are affected
  • Steps to Reproduce - How to reproduce the issue (if applicable)
  • Potential Impact - What could an attacker do with this vulnerability?
  • Suggested Fix - If you have a suggestion for fixing the issue (optional)
  • Your Contact Information - How we can reach you if we need more details

Security Response Timeline

We will make our best effort to:

  1. Acknowledge receipt - Respond within 3-5 business days to confirm we received your report
  2. Investigate - Work to understand and reproduce the issue
  3. Develop a fix - Create and test a patch
  4. Coordinate disclosure - Work with you on a responsible disclosure timeline
  5. Release patch - Issue a security update and publicly disclose the vulnerability

Depending on the complexity and severity of the vulnerability, this process may take anywhere from a few days to a few weeks.

Disclosure Policy

We follow a responsible disclosure process:

  1. After receiving your report, we will work to verify and understand the vulnerability
  2. We will attempt to fix the issue and release a patch
  3. We will coordinate with you on the timing of public disclosure
  4. We will credit you in the security advisory if you wish (with your permission)
  5. We aim to have a patch available before public disclosure, when possible

Supported Versions

VersionStatusSecurity Updates
3.xLatest✅ Yes
2.xOlder⚠️ Case by case
1.xOutdated❌ No

We recommend users keep their application up to date with the latest version to ensure they have the latest security patches.

Security Considerations

Offline-First Architecture

MakeACopy is designed to work completely offline. This design choice significantly reduces certain classes of security risks:

  • ✅ No network requests to untrusted servers
  • ✅ No cloud storage of user data
  • ✅ No tracking or analytics
  • ✅ No third-party API dependencies

However, other security considerations remain important:

  • Input validation for document processing
  • Safe handling of OCR models and image processing
  • Secure storage of any cached data
  • Safe handling of file I/O operations

Dependencies

We carefully select and maintain our dependencies:

  • ONNX Runtime - ML inference engine for document detection
  • OpenCV - Image processing library
  • Tesseract/Leptonica - OCR engines

All dependencies are regularly updated to patch known vulnerabilities. We use tools like:

  • Gradle dependency scanning
  • GitHub's Dependabot for monitoring CVEs
  • Regular security audits

Code Review

All code changes, including security fixes, go through:

  • Code review by maintainers
  • Automated testing (unit and instrumented tests)
  • Lint checks and code quality analysis
  • Compatibility testing on multiple Android versions

Android Security Features

MakeACopy leverages Android's built-in security features:

  • Sandboxing - Each app instance is isolated from others
  • Permission System - Users must grant permissions for camera, storage, etc.
  • SELinux - Android's mandatory access control framework
  • Code Signing - All releases are cryptographically signed

Build Reproducibility

Official releases are built to be reproducible, allowing community members to verify builds:

  • Fixed tool versions (JDK, NDK, CMake)
  • Deterministic build process
  • Published build scripts and documentation
  • APK signature verification available

APK Verification

All official releases are cryptographically signed. You can verify the authenticity of APKs:

Upload Key (used for GitHub releases, F-Droid, and sideload APKs):

SHA-256: AE:32:2D:3F:B7:1A:FE:21:DF:47:27:E3:7A:5C:68:03:51:1D:5A:2F:E1:FC:31:35:43:0C:EE:06:99:FA:1B:34

Google Play App Signing Key:

  • Used for Play Store releases only

Staying Informed

To stay informed about security updates:

  • ⭐ Watch the GitHub repository for release notifications
  • 📧 Subscribe to release announcements
  • 🔔 Enable notifications for security advisories

Scope

This security policy covers:

  • The MakeACopy application code
  • Official releases (F-Droid, Google Play, GitHub Releases)
  • The project documentation and build infrastructure

This security policy does not cover:

  • Third-party forks or modified versions
  • Older versions beyond the supported versions listed above
  • Dependencies maintained by third parties (though we will help coordinate fixes)

Questions or Concerns?

If you have questions about this security policy or security in general, feel free to open a private security advisory or discussion in the repository.


Thank you for helping keep MakeACopy secure!

We appreciate the security research community and responsible disclosure practices that help make our project safer for all users.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Security: egdels/makeacopy

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

We take security seriously and appreciate your efforts to responsibly disclose any security vulnerabilities you discover.

How to Report

Please do NOT open a public GitHub issue for security vulnerabilities. Instead, please report security vulnerabilities to the project maintainers privately.

  1. Use GitHub's Security Advisory Form

  2. Or contact the maintainers directly

    • Send an email describing the vulnerability with details about:
      • The type of vulnerability
      • Location in the code (if applicable)
      • Potential impact
      • Any suggested fixes or workarounds

What to Include

Please provide as much information as possible to help us understand and assess the vulnerability:

  • Description - A clear description of the vulnerability
  • Affected Version(s) - Which version(s) of MakeACopy are affected
  • Steps to Reproduce - How to reproduce the issue (if applicable)
  • Potential Impact - What could an attacker do with this vulnerability?
  • Suggested Fix - If you have a suggestion for fixing the issue (optional)
  • Your Contact Information - How we can reach you if we need more details

Security Response Timeline

We will make our best effort to:

  1. Acknowledge receipt - Respond within 3-5 business days to confirm we received your report
  2. Investigate - Work to understand and reproduce the issue
  3. Develop a fix - Create and test a patch
  4. Coordinate disclosure - Work with you on a responsible disclosure timeline
  5. Release patch - Issue a security update and publicly disclose the vulnerability

Depending on the complexity and severity of the vulnerability, this process may take anywhere from a few days to a few weeks.

Disclosure Policy

We follow a responsible disclosure process:

  1. After receiving your report, we will work to verify and understand the vulnerability
  2. We will attempt to fix the issue and release a patch
  3. We will coordinate with you on the timing of public disclosure
  4. We will credit you in the security advisory if you wish (with your permission)
  5. We aim to have a patch available before public disclosure, when possible

Supported Versions

VersionStatusSecurity Updates
3.xLatest✅ Yes
2.xOlder⚠️ Case by case
1.xOutdated❌ No

We recommend users keep their application up to date with the latest version to ensure they have the latest security patches.

Security Considerations

Offline-First Architecture

MakeACopy is designed to work completely offline. This design choice significantly reduces certain classes of security risks:

  • ✅ No network requests to untrusted servers
  • ✅ No cloud storage of user data
  • ✅ No tracking or analytics
  • ✅ No third-party API dependencies

However, other security considerations remain important:

  • Input validation for document processing
  • Safe handling of OCR models and image processing
  • Secure storage of any cached data
  • Safe handling of file I/O operations

Dependencies

We carefully select and maintain our dependencies:

  • ONNX Runtime - ML inference engine for document detection
  • OpenCV - Image processing library
  • Tesseract/Leptonica - OCR engines

All dependencies are regularly updated to patch known vulnerabilities. We use tools like:

  • Gradle dependency scanning
  • GitHub's Dependabot for monitoring CVEs
  • Regular security audits

Code Review

All code changes, including security fixes, go through:

  • Code review by maintainers
  • Automated testing (unit and instrumented tests)
  • Lint checks and code quality analysis
  • Compatibility testing on multiple Android versions

Android Security Features

MakeACopy leverages Android's built-in security features:

  • Sandboxing - Each app instance is isolated from others
  • Permission System - Users must grant permissions for camera, storage, etc.
  • SELinux - Android's mandatory access control framework
  • Code Signing - All releases are cryptographically signed

Build Reproducibility

Official releases are built to be reproducible, allowing community members to verify builds:

  • Fixed tool versions (JDK, NDK, CMake)
  • Deterministic build process
  • Published build scripts and documentation
  • APK signature verification available

APK Verification

All official releases are cryptographically signed. You can verify the authenticity of APKs:

Upload Key (used for GitHub releases, F-Droid, and sideload APKs):

SHA-256: AE:32:2D:3F:B7:1A:FE:21:DF:47:27:E3:7A:5C:68:03:51:1D:5A:2F:E1:FC:31:35:43:0C:EE:06:99:FA:1B:34

Google Play App Signing Key:

  • Used for Play Store releases only

Staying Informed

To stay informed about security updates:

  • ⭐ Watch the GitHub repository for release notifications
  • 📧 Subscribe to release announcements
  • 🔔 Enable notifications for security advisories

Scope

This security policy covers:

  • The MakeACopy application code
  • Official releases (F-Droid, Google Play, GitHub Releases)
  • The project documentation and build infrastructure

This security policy does not cover:

  • Third-party forks or modified versions
  • Older versions beyond the supported versions listed above
  • Dependencies maintained by third parties (though we will help coordinate fixes)

Questions or Concerns?

If you have questions about this security policy or security in general, feel free to open a private security advisory or discussion in the repository.


Thank you for helping keep MakeACopy secure!

We appreciate the security research community and responsible disclosure practices that help make our project safer for all users.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: egdels/makeacopy

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

We take security seriously and appreciate your efforts to responsibly disclose any security vulnerabilities you discover.

How to Report

Please do NOT open a public GitHub issue for security vulnerabilities. Instead, please report security vulnerabilities to the project maintainers privately.

  1. Use GitHub's Security Advisory Form

  2. Or contact the maintainers directly

    • Send an email describing the vulnerability with details about:
      • The type of vulnerability
      • Location in the code (if applicable)
      • Potential impact
      • Any suggested fixes or workarounds

What to Include

Please provide as much information as possible to help us understand and assess the vulnerability:

  • Description - A clear description of the vulnerability
  • Affected Version(s) - Which version(s) of MakeACopy are affected
  • Steps to Reproduce - How to reproduce the issue (if applicable)
  • Potential Impact - What could an attacker do with this vulnerability?
  • Suggested Fix - If you have a suggestion for fixing the issue (optional)
  • Your Contact Information - How we can reach you if we need more details

Security Response Timeline

We will make our best effort to:

  1. Acknowledge receipt - Respond within 3-5 business days to confirm we received your report
  2. Investigate - Work to understand and reproduce the issue
  3. Develop a fix - Create and test a patch
  4. Coordinate disclosure - Work with you on a responsible disclosure timeline
  5. Release patch - Issue a security update and publicly disclose the vulnerability

Depending on the complexity and severity of the vulnerability, this process may take anywhere from a few days to a few weeks.

Disclosure Policy

We follow a responsible disclosure process:

  1. After receiving your report, we will work to verify and understand the vulnerability
  2. We will attempt to fix the issue and release a patch
  3. We will coordinate with you on the timing of public disclosure
  4. We will credit you in the security advisory if you wish (with your permission)
  5. We aim to have a patch available before public disclosure, when possible

Supported Versions

VersionStatusSecurity Updates
3.xLatest✅ Yes
2.xOlder⚠️ Case by case
1.xOutdated❌ No

We recommend users keep their application up to date with the latest version to ensure they have the latest security patches.

Security Considerations

Offline-First Architecture

MakeACopy is designed to work completely offline. This design choice significantly reduces certain classes of security risks:

  • ✅ No network requests to untrusted servers
  • ✅ No cloud storage of user data
  • ✅ No tracking or analytics
  • ✅ No third-party API dependencies

However, other security considerations remain important:

  • Input validation for document processing
  • Safe handling of OCR models and image processing
  • Secure storage of any cached data
  • Safe handling of file I/O operations

Dependencies

We carefully select and maintain our dependencies:

  • ONNX Runtime - ML inference engine for document detection
  • OpenCV - Image processing library
  • Tesseract/Leptonica - OCR engines

All dependencies are regularly updated to patch known vulnerabilities. We use tools like:

  • Gradle dependency scanning
  • GitHub's Dependabot for monitoring CVEs
  • Regular security audits

Code Review

All code changes, including security fixes, go through:

  • Code review by maintainers
  • Automated testing (unit and instrumented tests)
  • Lint checks and code quality analysis
  • Compatibility testing on multiple Android versions

Android Security Features

MakeACopy leverages Android's built-in security features:

  • Sandboxing - Each app instance is isolated from others
  • Permission System - Users must grant permissions for camera, storage, etc.
  • SELinux - Android's mandatory access control framework
  • Code Signing - All releases are cryptographically signed

Build Reproducibility

Official releases are built to be reproducible, allowing community members to verify builds:

  • Fixed tool versions (JDK, NDK, CMake)
  • Deterministic build process
  • Published build scripts and documentation
  • APK signature verification available

APK Verification

All official releases are cryptographically signed. You can verify the authenticity of APKs:

Upload Key (used for GitHub releases, F-Droid, and sideload APKs):

SHA-256: AE:32:2D:3F:B7:1A:FE:21:DF:47:27:E3:7A:5C:68:03:51:1D:5A:2F:E1:FC:31:35:43:0C:EE:06:99:FA:1B:34

Google Play App Signing Key:

  • Used for Play Store releases only

Staying Informed

To stay informed about security updates:

  • ⭐ Watch the GitHub repository for release notifications
  • 📧 Subscribe to release announcements
  • 🔔 Enable notifications for security advisories

Scope

This security policy covers:

  • The MakeACopy application code
  • Official releases (F-Droid, Google Play, GitHub Releases)
  • The project documentation and build infrastructure

This security policy does not cover:

  • Third-party forks or modified versions
  • Older versions beyond the supported versions listed above
  • Dependencies maintained by third parties (though we will help coordinate fixes)

Questions or Concerns?

If you have questions about this security policy or security in general, feel free to open a private security advisory or discussion in the repository.


Thank you for helping keep MakeACopy secure!

We appreciate the security research community and responsible disclosure practices that help make our project safer for all users.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: egdels/makeacopy

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

We take security seriously and appreciate your efforts to responsibly disclose any security vulnerabilities you discover.

How to Report

Please do NOT open a public GitHub issue for security vulnerabilities. Instead, please report security vulnerabilities to the project maintainers privately.

  1. Use GitHub's Security Advisory Form

  2. Or contact the maintainers directly

    • Send an email describing the vulnerability with details about:
      • The type of vulnerability
      • Location in the code (if applicable)
      • Potential impact
      • Any suggested fixes or workarounds

What to Include

Please provide as much information as possible to help us understand and assess the vulnerability:

  • Description - A clear description of the vulnerability
  • Affected Version(s) - Which version(s) of MakeACopy are affected
  • Steps to Reproduce - How to reproduce the issue (if applicable)
  • Potential Impact - What could an attacker do with this vulnerability?
  • Suggested Fix - If you have a suggestion for fixing the issue (optional)
  • Your Contact Information - How we can reach you if we need more details

Security Response Timeline

We will make our best effort to:

  1. Acknowledge receipt - Respond within 3-5 business days to confirm we received your report
  2. Investigate - Work to understand and reproduce the issue
  3. Develop a fix - Create and test a patch
  4. Coordinate disclosure - Work with you on a responsible disclosure timeline
  5. Release patch - Issue a security update and publicly disclose the vulnerability

Depending on the complexity and severity of the vulnerability, this process may take anywhere from a few days to a few weeks.

Disclosure Policy

We follow a responsible disclosure process:

  1. After receiving your report, we will work to verify and understand the vulnerability
  2. We will attempt to fix the issue and release a patch
  3. We will coordinate with you on the timing of public disclosure
  4. We will credit you in the security advisory if you wish (with your permission)
  5. We aim to have a patch available before public disclosure, when possible

Supported Versions

VersionStatusSecurity Updates
3.xLatest✅ Yes
2.xOlder⚠️ Case by case
1.xOutdated❌ No

We recommend users keep their application up to date with the latest version to ensure they have the latest security patches.

Security Considerations

Offline-First Architecture

MakeACopy is designed to work completely offline. This design choice significantly reduces certain classes of security risks:

  • ✅ No network requests to untrusted servers
  • ✅ No cloud storage of user data
  • ✅ No tracking or analytics
  • ✅ No third-party API dependencies

However, other security considerations remain important:

  • Input validation for document processing
  • Safe handling of OCR models and image processing
  • Secure storage of any cached data
  • Safe handling of file I/O operations

Dependencies

We carefully select and maintain our dependencies:

  • ONNX Runtime - ML inference engine for document detection
  • OpenCV - Image processing library
  • Tesseract/Leptonica - OCR engines

All dependencies are regularly updated to patch known vulnerabilities. We use tools like:

  • Gradle dependency scanning
  • GitHub's Dependabot for monitoring CVEs
  • Regular security audits

Code Review

All code changes, including security fixes, go through:

  • Code review by maintainers
  • Automated testing (unit and instrumented tests)
  • Lint checks and code quality analysis
  • Compatibility testing on multiple Android versions

Android Security Features

MakeACopy leverages Android's built-in security features:

  • Sandboxing - Each app instance is isolated from others
  • Permission System - Users must grant permissions for camera, storage, etc.
  • SELinux - Android's mandatory access control framework
  • Code Signing - All releases are cryptographically signed

Build Reproducibility

Official releases are built to be reproducible, allowing community members to verify builds:

  • Fixed tool versions (JDK, NDK, CMake)
  • Deterministic build process
  • Published build scripts and documentation
  • APK signature verification available

APK Verification

All official releases are cryptographically signed. You can verify the authenticity of APKs:

Upload Key (used for GitHub releases, F-Droid, and sideload APKs):

SHA-256: AE:32:2D:3F:B7:1A:FE:21:DF:47:27:E3:7A:5C:68:03:51:1D:5A:2F:E1:FC:31:35:43:0C:EE:06:99:FA:1B:34

Google Play App Signing Key:

  • Used for Play Store releases only

Staying Informed

To stay informed about security updates:

  • ⭐ Watch the GitHub repository for release notifications
  • 📧 Subscribe to release announcements
  • 🔔 Enable notifications for security advisories

Scope

This security policy covers:

  • The MakeACopy application code
  • Official releases (F-Droid, Google Play, GitHub Releases)
  • The project documentation and build infrastructure

This security policy does not cover:

  • Third-party forks or modified versions
  • Older versions beyond the supported versions listed above
  • Dependencies maintained by third parties (though we will help coordinate fixes)

Questions or Concerns?

If you have questions about this security policy or security in general, feel free to open a private security advisory or discussion in the repository.


Thank you for helping keep MakeACopy secure!

We appreciate the security research community and responsible disclosure practices that help make our project safer for all users.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Security: egdels/makeacopy

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

We take security seriously and appreciate your efforts to responsibly disclose any security vulnerabilities you discover.

How to Report

Please do NOT open a public GitHub issue for security vulnerabilities. Instead, please report security vulnerabilities to the project maintainers privately.

  1. Use GitHub's Security Advisory Form

  2. Or contact the maintainers directly

    • Send an email describing the vulnerability with details about:
      • The type of vulnerability
      • Location in the code (if applicable)
      • Potential impact
      • Any suggested fixes or workarounds

What to Include

Please provide as much information as possible to help us understand and assess the vulnerability:

  • Description - A clear description of the vulnerability
  • Affected Version(s) - Which version(s) of MakeACopy are affected
  • Steps to Reproduce - How to reproduce the issue (if applicable)
  • Potential Impact - What could an attacker do with this vulnerability?
  • Suggested Fix - If you have a suggestion for fixing the issue (optional)
  • Your Contact Information - How we can reach you if we need more details

Security Response Timeline

We will make our best effort to:

  1. Acknowledge receipt - Respond within 3-5 business days to confirm we received your report
  2. Investigate - Work to understand and reproduce the issue
  3. Develop a fix - Create and test a patch
  4. Coordinate disclosure - Work with you on a responsible disclosure timeline
  5. Release patch - Issue a security update and publicly disclose the vulnerability

Depending on the complexity and severity of the vulnerability, this process may take anywhere from a few days to a few weeks.

Disclosure Policy

We follow a responsible disclosure process:

  1. After receiving your report, we will work to verify and understand the vulnerability
  2. We will attempt to fix the issue and release a patch
  3. We will coordinate with you on the timing of public disclosure
  4. We will credit you in the security advisory if you wish (with your permission)
  5. We aim to have a patch available before public disclosure, when possible

Supported Versions

VersionStatusSecurity Updates
3.xLatest✅ Yes
2.xOlder⚠️ Case by case
1.xOutdated❌ No

We recommend users keep their application up to date with the latest version to ensure they have the latest security patches.

Security Considerations

Offline-First Architecture

MakeACopy is designed to work completely offline. This design choice significantly reduces certain classes of security risks:

  • ✅ No network requests to untrusted servers
  • ✅ No cloud storage of user data
  • ✅ No tracking or analytics
  • ✅ No third-party API dependencies

However, other security considerations remain important:

  • Input validation for document processing
  • Safe handling of OCR models and image processing
  • Secure storage of any cached data
  • Safe handling of file I/O operations

Dependencies

We carefully select and maintain our dependencies:

  • ONNX Runtime - ML inference engine for document detection
  • OpenCV - Image processing library
  • Tesseract/Leptonica - OCR engines

All dependencies are regularly updated to patch known vulnerabilities. We use tools like:

  • Gradle dependency scanning
  • GitHub's Dependabot for monitoring CVEs
  • Regular security audits

Code Review

All code changes, including security fixes, go through:

  • Code review by maintainers
  • Automated testing (unit and instrumented tests)
  • Lint checks and code quality analysis
  • Compatibility testing on multiple Android versions

Android Security Features

MakeACopy leverages Android's built-in security features:

  • Sandboxing - Each app instance is isolated from others
  • Permission System - Users must grant permissions for camera, storage, etc.
  • SELinux - Android's mandatory access control framework
  • Code Signing - All releases are cryptographically signed

Build Reproducibility

Official releases are built to be reproducible, allowing community members to verify builds:

  • Fixed tool versions (JDK, NDK, CMake)
  • Deterministic build process
  • Published build scripts and documentation
  • APK signature verification available

APK Verification

All official releases are cryptographically signed. You can verify the authenticity of APKs:

Upload Key (used for GitHub releases, F-Droid, and sideload APKs):

SHA-256: AE:32:2D:3F:B7:1A:FE:21:DF:47:27:E3:7A:5C:68:03:51:1D:5A:2F:E1:FC:31:35:43:0C:EE:06:99:FA:1B:34

Google Play App Signing Key:

  • Used for Play Store releases only

Staying Informed

To stay informed about security updates:

  • ⭐ Watch the GitHub repository for release notifications
  • 📧 Subscribe to release announcements
  • 🔔 Enable notifications for security advisories

Scope

This security policy covers:

  • The MakeACopy application code
  • Official releases (F-Droid, Google Play, GitHub Releases)
  • The project documentation and build infrastructure

This security policy does not cover:

  • Third-party forks or modified versions
  • Older versions beyond the supported versions listed above
  • Dependencies maintained by third parties (though we will help coordinate fixes)

Questions or Concerns?

If you have questions about this security policy or security in general, feel free to open a private security advisory or discussion in the repository.


Thank you for helping keep MakeACopy secure!

We appreciate the security research community and responsible disclosure practices that help make our project safer for all users.

There aren't any published security advisories