Skip to content

Security: jasonssdev/whisper-loopback

Security

SECURITY.md

Security Policy

Supported versions

Version Supported
0.1.x / latest main Yes
Anything older No

Reporting a vulnerability

Please report vulnerabilities privately via GitHub Security Advisories: go to the repository's Security tab and click "Report a vulnerability" (https://github.com/jasonssdev/whisper-loopback/security/advisories/new).

Do not open a public issue for security vulnerabilities.

If advisory reporting is unavailable to you for any reason, email the maintainer directly at jasonssdev@gmail.com with "SECURITY" in the subject.

This project has a single maintainer, so responses are best-effort — you can expect an initial acknowledgement within a few days, and a fix or mitigation as soon as practical after triage.

Scope

whisper-loopback is a fully-local application: it runs no servers, requires no account or API key, and audio and transcripts never leave the machine. The optional Ollama summary integration talks only to a user-configured local endpoint (http://localhost:11434 by default). Reports about data leaving the machine unexpectedly, privilege escalation, or unsafe handling of local files are especially relevant.

There aren't any published security advisories