Security fixes currently target the latest published release.
Use GitHub's private vulnerability reporting feature if it is available under the repository's Security tab. If private reporting is unavailable, open a public issue that contains no exploit details or private data and ask for a private contact channel.
Do not publish typed text, clipboard contents, snippets, signing material or a working exploit in a public issue.
Include:
- The affected Expanda version and Android version.
- The security impact.
- Reproduction steps using fictional data.
- Any suggested mitigation.
Regular compatibility bugs belong in the public issue tracker.