Security fixes are applied to the newest TempoLatch release and the default branch.
Use the repository's Security → Report a vulnerability flow. Include:
- affected TempoLatch version and Windows build;
- whether the operation was Preview or Apply;
- the smallest reproduction that demonstrates the problem;
- relevant evidence JSON with account names, SIDs, and local paths redacted;
- expected versus observed file, ACL, registry, or process state.
Do not include Spotify credentials, cookies, access tokens, full profile archives, or proprietary installer binaries.
TempoLatch protects its own mutation scope; it is not a sandbox or access-control product. Reports are especially useful for path traversal, reparse-point handling, DACL restoration, archive verification, signature validation, unsafe rollback, command-line parsing, and unintended process execution.