Skip to content

Security: mdktdys/jira-markdown-export

Security

SECURITY.md

Security policy

Supported versions

Security fixes are applied to the latest release and the default branch.

Reporting a vulnerability

Please use GitHub's private Report a vulnerability form in the repository's Security tab. If private vulnerability reporting is not enabled yet, contact the repository owner through the contact method listed on their GitHub profile without publishing exploit details.

Include:

  • the affected version or commit;
  • the Safari and macOS versions;
  • a minimal reproduction using synthetic Jira content;
  • the expected impact;
  • any suggested mitigation.

Do not include real Jira credentials, cookies, private URLs, customer data, or exported archives.

Security model

Jira Markdown Export intentionally has no analytics, third-party backend, or Jira REST API integration. It reads the currently rendered page and may retrieve only image or attachment URLs found in that page using the existing Safari session. Exported content is created locally and downloaded through Safari.

When sharing an export outside the organization, users can enable Anonymize all links to replace every HTTP/HTTPS domain with the reserved example.com domain. Exact-host and wildcard exception rules can preserve explicitly selected domains.

Users can separately enable Anonymize IP addresses to replace recognized IPv4 and IPv6 values in Markdown, links, fallback logs, and packaged resource names with documentation-safe addresses. Exact-address and wildcard exception rules can preserve selected IP ranges or hosts. All rules are validated and stored only in Safari's local extension storage.

Anonymization intentionally preserves URL paths, query parameters, anchors, and other issue content. It is a sharing aid, not a general-purpose data-loss-prevention system, so users should review completed exports for other confidential values before distribution.

The extension requests broad HTTP/HTTPS host access because self-hosted Jira domains cannot be known in advance. The popup enables export only when the page parser recognizes an issue.

There aren't any published security advisories