Security fixes are provided for the latest published FootageFlow release.
FootageFlow v0.12.1 supports macOS 15+ on Apple Silicon and Windows 11 x64.
Please do not open a public issue for a credential leak, unsafe file operation, remote-code-execution risk, or another vulnerability that could harm users. Use the repository's private Security → Report a vulnerability form. Include affected version, reproduction steps, impact, and any suggested mitigation.
Do not include real API keys, private media, or personal file paths. Replace them with safe placeholders.
- API keys are stored through the operating system's secure credential store.
- Only HTTPS provider URLs without embedded credentials are accepted.
- Logs redact authorization, cookie, password, token, and API-key patterns.
- FootageFlow does not execute downloaded media, shell commands, or provider-supplied scripts.
- App-initiated local deletion is restricted to the configured download root and requires explicit confirmation.
- The repository's secret scan is a safety net, not a substitute for review.
- Update metadata is accepted only from the official GitHub Releases API, and update links are restricted to this repository's HTTPS release pages.
- The updater is notification-only: it cannot silently download, execute, or install a release.
The v0.12.1 macOS build is Ad Hoc signed and not notarized. The v0.12.1 Windows installer is not code-signed. These are distribution limitations, not claims of Apple or Microsoft verification. Release assets include SHA-256 checksums for independent verification.