| Version | Supported |
|---|---|
0.1.x / latest main |
Yes |
| Anything older | No |
Please report vulnerabilities privately via GitHub Security Advisories: go to the repository's Security tab and click "Report a vulnerability" (https://github.com/jasonssdev/whisper-loopback/security/advisories/new).
Do not open a public issue for security vulnerabilities.
If advisory reporting is unavailable to you for any reason, email the maintainer directly at jasonssdev@gmail.com with "SECURITY" in the subject.
This project has a single maintainer, so responses are best-effort — you can expect an initial acknowledgement within a few days, and a fix or mitigation as soon as practical after triage.
whisper-loopback is a fully-local application: it runs no servers, requires no
account or API key, and audio and transcripts never leave the machine. The
optional Ollama summary integration talks only to a user-configured local
endpoint (http://localhost:11434 by default). Reports about data leaving the
machine unexpectedly, privilege escalation, or unsafe handling of local files
are especially relevant.