Coordinated Vulnerability Disclosure Policy

This policy describes how MacWinlink handles security vulnerability
reports. It complements SECURITY.md (which tells reporters how
to reach us) by describing what happens next once a report is
received: how we triage, how we coordinate a fix, how we credit
reporters, and how we publish advisories.

MacWinlink is developed and distributed by the Amateur Radio Safety
Foundation, Inc. (ARSFI)
as part of the
Winlink Global Radio Email service. This policy applies to the
MacWinlink main app (bundle identifier org.arsfi.macwinlink) and
the MacWinlink Helper app (bundle identifier
org.arsfi.macwinlink-helper).

Our commitments

Guidance for reporters

If you believe you have found a security vulnerability in MacWinlink
or MacWinlink Helper, please:

Research conducted in good faith in accordance with this policy is
authorized: we will not initiate legal action, we will work with
you to resolve the issue, and we will credit you appropriately.
Research that violates this policy — or that violates applicable
law, or the FCC Part 97 rules governing amateur radio, or the terms
of ARSFI's provision of Winlink services — is not covered by this
authorization.

Our process

1. Acknowledgement (within 7 days)

You will receive a human acknowledgement that your report has been
received, from a person named or identifiable to ARSFI or MacWinlink
maintenance. If you have not heard back within 7 days, please
resend — email delivery to specialized aliases occasionally fails
silently.

2. Triage (within 30 days)

We assign a severity level (Critical, High, Medium, Low) based on
FIRST CVSS 3.1
scoring adapted for MacWinlink's context. Amateur-radio-specific
scoring considerations:

We will tell you our severity assessment and confirm we can
reproduce the issue. If we cannot reproduce, we will ask for
additional detail before dropping the report; we will not close
reports as "cannot reproduce" without dialogue.

3. Fix development

Fix timelines target:

We will keep you informed of progress at reasonable intervals. If
the fix turns out to be more complex than initially assessed, we
will tell you and revise the timeline together.

4. Coordination window

Default: 90 days from initial report to public disclosure.

We may shorten the window if:

We may lengthen the window if:

We will not extend the window unilaterally without discussing it
with you.

5. Release + advisory publication

When the fix ships, we publish a security advisory at
https://downloads.winlink.org/User%20Programs/MacWinlink/ containing:

The advisory is dated and appears in the security section's index
so operators can review the full history of advisories issued
against their installed version.

6. CVE assignment

If a CVE identifier is warranted for the vulnerability — typically
for Critical or High-severity issues, or for any issue where
downstream vulnerability databases would benefit from a stable
reference — ARSFI will request one from
MITRE at the time the advisory is
published. We do not have a CVE Numbering Authority (CNA)
arrangement of our own; MITRE-issued identifiers are the current
path.

Not every advisory gets a CVE. Low-severity issues, or issues that
affect only unreleased beta versions and are fixed before the next
public release, may be documented without CVE assignment.

What we will not do

Multi-vendor coordination

Some vulnerabilities affect components beyond MacWinlink — the
Winlink CMS, RMS Relay software, other Winlink clients, upstream
open-source dependencies like Direwolf or Hamlib, or Apple system
components. When this happens:

Applicable regulation

This policy is written to satisfy:

Changes to this policy

We will publish material changes to this policy at
https://downloads.winlink.org/User%20Programs/MacWinlink/ and note the
date of change. Reports submitted before a policy change are
handled under the policy in effect at the time of the report.

Last revised: 2026-08-24.