We actively support the following versions with security updates:
| Version | Supported | Security Updates |
|---|---|---|
| 1.0.x | β | β |
| < 1.0 | β | β |
If you discover a security vulnerability in Clipboard History, please help us by reporting it responsibly.
Please DO NOT report security vulnerabilities through public GitHub issues.
Instead, please report security vulnerabilities by emailing:
- Email: security@clipboardhistory.com
- Subject:
[SECURITY] Vulnerability Report
When reporting a security vulnerability, please include:
- Description: A clear description of the vulnerability
- Impact: What an attacker could achieve by exploiting this vulnerability
- Steps to Reproduce: Detailed steps to reproduce the issue
- Environment: App version, Android version, device information
- Proof of Concept: If possible, include a proof of concept
- Initial Response: Within 24 hours
- Vulnerability Assessment: Within 72 hours
- Fix Development: Within 1-2 weeks for critical issues
- Public Disclosure: After fix is deployed and tested
- All clipboard data is encrypted using SQLCipher
- AES-256-GCM encryption for sensitive data
- Secure key generation and storage
- Biometric authentication support
- Secure clipboard access permissions
- Background service restrictions
- Certificate pinning for secure communications
- HTTPS-only network requests
- No unnecessary network permissions
- Regular security audits and dependency scanning
- ProGuard/R8 obfuscation for release builds
- No hardcoded secrets or API keys
We use automated security scanning tools:
- CodeQL: Static analysis for security vulnerabilities
- OWASP Dependency Check: Third-party library vulnerability scanning
- Android Lint: Android-specific security checks
- Manual Security Audits: Quarterly comprehensive reviews
For security-related questions or concerns:
- Email: security@clipboardhistory.com
- PGP Key: Available upon request for encrypted communications
We appreciate security researchers who help keep our users safe. With your permission, we will acknowledge your contribution in our security advisories.
Security updates will be:
- Released as patch versions (e.g., 1.0.1, 1.0.2)
- Documented in release notes with CVE identifiers
- Communicated through GitHub Security Advisories
- Distributed through automated updates
Last Updated: December 5, 2024