Security fixes are applied to the latest release. Users should upgrade before reporting an issue that may already be resolved.
Do not open a public issue for a suspected vulnerability. Use GitHub's Security tab to submit a private vulnerability report.
Include the affected version, operating system, reproduction steps, potential impact, and any suggested mitigation. You should receive an acknowledgement within seven days. Please allow reasonable time for investigation and a coordinated fix before public disclosure.
FreeFlow handles microphone input, clipboard contents, and synthetic keyboard events. Reports involving unsafe file handling, privilege boundaries, command injection, or unintended disclosure are especially valuable.