Skip to content

Security: devxrohan/SMusic

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest released version of SMusic receives security updates. Older versions are not patched — please update to the latest release if you're reporting an issue.

Reporting a Vulnerability

If you discover a security vulnerability, please do not open a public issue. Public issues are visible to everyone, including anyone who might misuse the information before a fix is available.

Instead:

  1. Open a private security advisory on this repository (GitHub's "Report a vulnerability" option under the Security tab), or
  2. Contact the maintainer directly through GitHub.

Please include:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce it
  • The app version affected
  • Any suggested fix, if you have one

What to Expect

  • You'll receive an acknowledgment as soon as reasonably possible.
  • The issue will be investigated and, if confirmed, a fix will be prepared and released.
  • Once a fix is out, the report will be disclosed responsibly, with credit to the reporter if they'd like it.

Scope

This app talks to YouTube Music's public API and does not require you to sign in with a real Google account for core playback/streaming functionality. Be mindful when reporting issues that involve:

  • Any of your own personal account credentials or backup data
  • Third-party services this project integrates with (report those issues to the respective service instead, where applicable)

Thanks for helping keep SMusic and its users safe.

There aren't any published security advisories