Security fixes are provided for the latest published 0.1.x release during the initial public-preview period.
Use GitHub private vulnerability reporting. Do not open a public issue for a vulnerability.
Do not attach private XLSX files, comparison reports, local paths, credentials, or company data. A minimal synthetic workbook and clear reproduction steps are preferred. ZCompare does not currently create diagnostic log files or upload diagnostics automatically.
The project aims to acknowledge a report within seven days. This is a volunteer-maintained project, so response and fix timelines may vary.