| Version | Supported | Status |
|---|---|---|
15.0.x |
✅ | Active release stream |
< 15.0 |
❌ | End of Life / Unsupported |
- 100% Local-First & Zero-Egress: ProFiler operates strictly locally on your workstation. It performs no remote network telemetry, does not upload files to cloud servers, and requires no online account.
- Session-Only Secrets: PDF passwords and temporary decryption credentials are held only in volatile process memory and are never serialized to configuration files or logs.
- Redacted Data Exchange: Exporting workspace snapshots automatically strips host-specific absolute paths, system tokens, and untracked file metadata.
- Non-Elevation: The application operates with standard user privileges under
%LOCALAPPDATA%\ProFilerSuite(or standard XDG directories on POSIX) without requiring administrative elevation.
If you discover a security vulnerability, please report it privately:
- GitHub Security Advisories: Navigate to the Security tab of this repository and select Report a vulnerability.
- Direct Contact: If GitHub reporting is unavailable, contact the security team via
security@open-bricks.org,lukas@open-bricks.org, orsupport@lukasgeiger.com.
Please do not open public issues for security vulnerabilities.
We acknowledge receipt of vulnerability reports within 48 hours and provide a formal triage assessment within 5 business days, with regular progress updates until a patch is released.
Security fixes are released promptly upon confirmation and documented in CHANGELOG.md.
| Version | Unterstützt | Status |
|---|---|---|
15.0.x |
✅ | Aktiver Versionszweig |
< 15.0 |
❌ | Nicht mehr unterstützt (End of Life) |
- 100% Local-First & Zero-Egress: ProFiler arbeitet ausnahmslos lokal. Keine Netzwerk-Telemetrie, kein Cloud-Upload, kein Online-Konto.
- Flüchtige Passwörter (Session-Only): PDF-Passwörter und Schlüssel verbleiben ausschließlich im flüchtigen Arbeitsspeicher und werden niemals auf Datenträgern oder in Konfigurationsdateien gespeichert.
- Redigierter Datenaustausch: Der Workspace-Export entfernt automatisch system-spezifische absolute Pfade und vertrauliche Schlüssel.
- Unprivilegierter Betrieb (Non-Elevation): Die Anwendung läuft mit Standard-Benutzerrechten unter
%LOCALAPPDATA%\ProFilerSuite(bzw. XDG unter POSIX) und benötigt keine Administratorrechte.
Wenn Sie eine Sicherheitslücke entdecken, melden Sie diese bitte vertraulich:
- GitHub Security Advisories: Über den Reiter Security im Repository -> Report a vulnerability.
- Direktkontakt: Falls GitHub nicht nutzbar ist, per E-Mail an
security@open-bricks.org,lukas@open-bricks.orgodersupport@lukasgeiger.com.
Bitte eröffnen Sie keine öffentlichen Issues für Sicherheitslücken.
Wir bestätigen den Eingang innerhalb von 48 Stunden, führen innerhalb von 5 Werktagen eine strukturierte Triage durch und informieren regelmäßig über den Fortschritt bis zur Veröffentlichung eines Patches.
Sicherheitsupdates werden schnellstmöglich bereitgestellt und im CHANGELOG.md dokumentiert.