Skip to content

Latest commit

 

History

History
20 lines (12 loc) · 1.1 KB

File metadata and controls

20 lines (12 loc) · 1.1 KB

Security Policy

PortKill can send signals to processes on your Mac, so safety bugs matter. Examples: bypassing the read-only rules (PID 0/1, its own process, other users' processes), signalling the wrong process, or any unexpected network access.

Reporting a vulnerability

Please do not open a public issue. Report it privately through GitHub: Report a vulnerability

Include the macOS version, PortKill version, and steps to reproduce. You can expect an acknowledgement within a few days.

Supported versions

Only the latest release receives fixes.

What PortKill does and doesn't do

  • Runs lsof and ps locally, and sends SIGTERM or SIGKILL only to processes owned by the current user.
  • Collects no data. Its only network request is a single call to api.github.com when you choose "Check for Updates…"; it never checks automatically. Docker is queried only through a local unix socket, never a remote host.
  • Is not sandboxed, because it needs to inspect other processes. It uses the Hardened Runtime with no extra entitlements.