Thank you for helping keep MacWinlink and its users safe.
MacWinlink is developed and distributed by the Amateur Radio Safety
Foundation, Inc. (ARSFI) as part of the
Winlink Global Radio Email service. MacWinlink comprises two
independently versioned applications that ship on separate release
cadences:
0.99.N during the public beta and1.0.0 and later at general availability.1.0.0-betaN during public beta and 1.0.0 and later at generalSecurity fixes are applied to the current release of each
application only. Users are expected to update to the latest
released version.
| Version | Supported |
|---|---|
| Current released MacWinlink + Helper | ✅ |
| Prior beta versions | ❌ — please upgrade |
| Pre-beta releases (v0.9.x and earlier) | ❌ — please upgrade |
Once MacWinlink reaches its 1.0.0 general availability release,
ARSFI will publish a formal product-lifetime statement describing
how long each major version will receive security updates. During
the public beta cycle, security updates ship in the next beta.
Please do not report security vulnerabilities through public
forums, issue trackers, mailing lists, or social media.
Report privately by email to [SECURITY_EMAIL_PLACEHOLDER].
⚠️ Security reporting address is being provisioned.
The address above is a placeholder — the ARSFI security contact
address is currently being provisioned. Until this notice is
removed and a real address is in place, please file security
reports privately by opening a new discussion thread on the
Winlink Programs Google Group (private message the group
owners rather than posting publicly), and mark the subject line
[MacWinlink SECURITY]. We will update this document with the
permanent address as soon as it is live.
When the permanent address is in place, it will route to the
MacWinlink maintainer and a small, defined ARSFI escalation list.
Nothing else will route to that address; expect a human response,
not an automated reply.
Encrypted email will be welcome but not required. If you would
like to encrypt your report, request the current PGP key at the
same address and wait for the reply before sending the report
body.
When reporting, please include:
We aim to:
For vulnerabilities that qualify as "actively exploited" or
"severe incidents" under the EU Cyber Resilience Act (Regulation
(EU) 2024/2847), Article 14 applies: ARSFI will issue an early
warning to ENISA within 24 hours of becoming aware, a notification
within 72 hours, and a final report within 14 days. This is handled
internally by ARSFI; reporters do not need to take any action beyond
the initial private report.
In scope:
MacWinlink.app, bundle identifierorg.arsfi.macwinlink).MacWinlink Helper.app, bundleorg.arsfi.macwinlink-helper).Out of scope — please report to the appropriate upstream:
ardopcf (the bundled ARDOP modem) — report toIf you are unsure whether an issue is in scope, please report it
privately using the channels above and we will help you route it.
For non-security bugs, feature requests, and general support:
app:helper.app:bothFiling non-security issues through the security address above
slows both classes of report down.
We are happy to publicly credit reporters in the release notes for
the release that ships the fix and in the security advisory
published on the MacWinlink downloads area. If you prefer to
remain anonymous or use a handle, please tell us when you report.
MacWinlink follows a coordinated-disclosure model: