Security fixes are made against the latest release. Far currently has no automatic updater; install updates from GitHub Releases.
Please report vulnerabilities privately using GitHub private vulnerability reporting. Include the affected version, reproduction steps, and impact. Do not include credentials or personal activity data.
For ordinary bugs and feature requests, use Issues.
The first release is ad-hoc signed and not notarized by Apple. Download binaries only from this repository’s releases, or build the source yourself. Release archives include SHA-256 checksums to detect an incomplete or changed download; these checksums are not a substitute for Developer ID signing.