RetroMac is distributed as a notarized macOS app. Only the latest released version receives security updates.
| Version | Supported |
|---|---|
| 2.3 | ✅ |
| < 2.3 | ❌ |
Please report security vulnerabilities privately — do not open a public issue for a suspected vulnerability.
Preferred: use GitHub's private vulnerability reporting via the Security tab of this repository → "Report a vulnerability". This keeps the report private until a fix is available.
Alternatively, email maik.klotz@gmail.com with:
- a description of the issue and its impact,
- steps to reproduce (or a proof of concept),
- the RetroMac version and macOS version affected.
- Acknowledgement: within 5 business days.
- Status update: within 10 business days, including whether the report is accepted and an expected timeline for a fix.
- Disclosure: once a fix is released, we are happy to credit you in the release notes if you wish.
Thank you for helping keep RetroMac and its users safe.