| Version | Supported |
|---|---|
| 0.1.x (latest) | ✅ |
Older versions receive no security fixes once a newer minor version is released.
Please do not file public GitHub issues for security vulnerabilities.
You have two options:
Use GitHub's built-in private reporting: Report a vulnerability
This creates a private advisory visible only to you and the maintainer.
Email abdo-essam@hotmail.com with:
- A description of the vulnerability
- Steps to reproduce
- Affected platform(s) and OS version(s)
- Any suggested fix or workaround (optional)
| Step | Target |
|---|---|
| Acknowledgement | Within 48 hours |
| Initial assessment | Within 5 business days |
| Fix or mitigation | Depends on severity |
ComposeShield provides the strongest screen-capture protection each platform officially supports. The following are out of scope by design — they are platform limitations, not library bugs:
- Physical observation of the screen (camera, shoulder-surfing)
- Capture on rooted or jailbroken devices
- ADB
screencapbypassingFLAG_SECUREon rooted Android - Simulator / emulator — OS-level protection is not enforced there
See docs/security-limitations.md for the full boundary.