Erfana is an Electron desktop application (GPL-3.0-only). It runs an integrated terminal (PTY), reads and writes the user's project files, can download and verify local Whisper binaries, and ships a release-artifact trust chain. We take security reports seriously.
Please report security issues privately — do not open a public issue, pull request, or discussion for an unfixed vulnerability.
- Preferred: use GitHub's private vulnerability reporting (the "Report a vulnerability" button under the repository's Security tab). This keeps the report confidential between you and the maintainers until a fix ships.
- If private reporting is unavailable to you: open a minimal public issue with no exploit details — just ask the maintainers to open a private channel — and we will follow up.
Please include: the affected component or file(s), the Erfana version (Help → About, or the app's version string), your OS, reproduction steps or a proof of concept, the impact, and any suggested remediation. We aim to acknowledge a report within a few business days and will credit reporters who wish to be named once a fix is released.
In scope:
- The Electron main process services (
src/main/) — file, terminal/PTY, project, settings, git-status, watcher, screenshot, camera, transcription, and import services. - The preload context bridge (
src/preload/) and the IPC layer (src/shared/ipc/,src/main/ipc/) — sender validation, schema validation, and channel exposure. - The renderer (
src/renderer/) — CSP, sandboxing, and any HTML/markdown rendering surface. - The local Whisper trust chain: minisign dual-key manifest verification, artifact SHA-256 pinning, per-spawn TOCTOU re-hash, the
secureDownloaderhostname allowlist, and argv hardening (validateAudioPath). - The release pipeline: signed tags, GitHub Actions workflows, and the minisign-signed
SHA256SUMSrelease-artifact trust chain (seedocs/build/release.mdanddocs/security.md).
Out of scope:
- The Anthropic Claude API and the
claudeCLI run inside the integrated terminal (report Claude issues to Anthropic atsecurity@anthropic.com). - A user's local environment configuration (OS, shell, installed binaries) and third-party tools invoked from the terminal.
- Vulnerabilities solely in upstream dependencies with no Erfana-specific exposure — report those upstream, though we appreciate a heads-up.
For Electron fuses, sandboxing, context isolation, CSP configuration, and audit history, see docs/security.md.
Every release on or after v0.9.5 ships signed artifacts. End users should verify downloads before installing — see README.md § Release verification and docs/security.md.
Until the #43 packaging-allowlist fix, electron-builder.yml's files: list was negation-only, so the packager copied the entire repository root into Contents/Resources/app/. Published releases were audited to bound the exposure:
- Audited: the published
v0.16.3macOS artifact (erfana-0.16.3-arm64.dmg), by mounting it and inspectingContents/Resources/app. Date: 2026-08-09. - What shipped: tracked development directories and files —
e2e/,specs/,scripts/,patches/,build/,.claude/{agents,settings.json,skills},.erfana/,eslint.config.mjs,playwright.config.tsand similar (18 top-level entries underapp/). This is bloat and non-runtime source disclosure of already-public GPL code. - What did NOT ship: no credential- or key-shaped files (
.env,.env.*,.npmrc,*.pem,*.key,id_*,*.local.json) anywhere in the bundle, including insidenode_modules; no secret-shaped values in the shipped config files (.mcp.json,.claude/settings.json,.erfana/settings.json); and no untracked, machine-local content — the gitignored.claude/settings.local.jsonwas absent, confirming releases are built from a cleanactions/checkoutwhere only tracked paths exist.
Conclusion: the impact on published releases is source disclosure and bundle bloat of already-public code, not confidentiality loss. The confidentiality half of the defect (untracked, mode-0700 local directories losing their permissions inside the bundle) only reproduces on local developer builds, never on a CI-built release. No advisory is warranted; the fix removes the disclosure and bloat going forward.
Erfana is at a 0.x stage. Only the latest released version receives security fixes.