| Version | Supported |
|---|---|
| 1.x | Yes |
| 0.x | No. Upgrade with docs/MIGRATION-1.0.md. |
Report privately through GitHub's private vulnerability reporting on the repository (Security tab, "Report a vulnerability"). Include the affected product (LumiKitCore, LumiKitUI, LumiKitPhoto, LumiKitDebug, LumiKitLottie), the version, and steps to reproduce.
You will get an acknowledgement within 7 days and a fix or a mitigation plan within 90 days of the report. Please keep the report private until a fix has shipped; the advisory credits the reporter unless asked otherwise.
LumiKitDebugcaptures HTTP traffic through aURLProtocolfor debugging. Its code is compiled only whenLMK_ENABLE_NETWORK_LOGGINGis defined, which the package sets for debug configurations. Do not define it in a release build. The logger redactsAuthorization,Cookie,Set-Cookie, andX-API-Keyheaders by default and accepts ahostFilterallowlist; captured payloads copied to the pasteboard expire.LMKURLValidatoris a literal host blocklist (loopback, private, link-local, carrier-grade NAT, multicast, unspecified). It does not resolve names, so it cannot catch a DNS record that points at a private address; resolve and re-check at request time when that matters.LMKLoggerwrites to the unified logging system withpublicmessage privacy by default. SetLMKLogger.messagePrivacy = .privatewhen messages may carry personal data.LMKPhotoMetadata.write(date:coordinate:to:)embeds a capture date and location into image bytes on request; the caller decides whether location data may leave the device.