← Viaduct

Security Policy

Last updated: July 15, 2026

Supported versions

Viaduct is a rolling release. Only the latest published build receives security fixes. If you are running an older build, update before reporting an issue.

Reporting a vulnerability

Please do not open a public issue for security vulnerabilities. Report privately through one of:

Please include:

What to expect

Please give a reasonable window to release a fix before any public disclosure.

Scope

Viaduct wraps the @magicelk235/viaduct command-line tool and can download extensions from the Chrome Web Store, sign them with your local Apple identity, and self-update the bundled CLI from npm. Reports touching any of these paths — CLI invocation, code signing, the viaduct:// URL scheme, or the auto-update flow — are in scope. Vulnerabilities in the upstream CLI package itself should be reported against that package.