Report a vulnerability

This page is the reporting channel for security vulnerabilities in Truffle and on this website — in the sense of the EU Cyber Resilience Act. It says where a report goes, what helps, and what you can expect from us afterwards. The German version is authoritative; this English text is provided for convenience.

Contact: security@truffle-app.com

Please do not file public bug reports for security-relevant findings. A publicly described flaw can be used by anyone from the moment it is published — including those who never intended to report it.

What helps in a report

A proof that the flaw can be exploited is welcome but not required. A report with gaps is better than no report.

What you can expect

Anyone who reports a vulnerability and gives us time to fix it will be credited in the release notes on request. Anyone who prefers to remain unnamed remains unnamed.

How a fix reaches you

A corrected, signed and Apple-notarised version is made available at download.truffle-app.com; reporters are notified. Truffle learns of it in two ways: it checks at launch and once a day, via the Sparkle update module, whether a new version is available, and the licence server names the current version to activated installations with every confirmation. In both cases Truffle shows you the update — it is downloaded and installed only once you confirm it. Until then the old version keeps running. For an actively exploited flaw the licence server can additionally retire older versions as a minimum version; activated installations then see the notice at least 30 days in advance (see the licence agreement, section 4).

Support period

The support period within the meaning of the EU Cyber Resilience Act is five years from the day a version was last offered for download, and applies from version 1.0 onwards. During this period reported vulnerabilities are handled within the time frames stated above and fixed versions are made available for download. Truffle is maintained as one line: security fixes are issued for the current version, older releases receive no backports — and the current version runs on the same systems as the one it replaces.

What Truffle does — and does not do

This belongs here because it describes the attack surface:

A software bill of materials listing the bundled third-party components exists and is provided on request to the same address.

As of 29 August 2026