Security notice

How security notices will work here

Where a vulnerability report goes, what happens next, and where the fix announcement will be published.

Before there is anything to announce, the process deserves to be written down.

Reports go to security@mountit.app. Mountit is small; a report is read by the person who can fix it, usually the one who wrote the code involved. We will not threaten you for one — the support page says so and this is it meaning the same thing.

When a fix ships, the announcement is published here with the Security notice label and mirrored in the changelog, tagged security. Security entries are never buried in “bug fixes and improvements”: an auto-updater that installs one silently denies you the one sentence that explains why the app restarted, and this page will not either.

The app has its own way to reach you first: signed announcements delivered inside Mountit, whose links are verified to point at this site and nowhere else. A security notice there and a security notice here are the same text, published the same day.

Both have an Atom feed, so you do not have to check by hand.