Skip to content

Latest commit

 

History

History
62 lines (42 loc) · 2.38 KB

SECURITY.md

File metadata and controls

62 lines (42 loc) · 2.38 KB

Security Policy

Supported Versions

The pleezer project is actively being developed, and we currently only support the latest version. We recommend users always update to the latest version of pleezer to ensure they have the most recent security updates and fixes.

Version Supported
Latest
< Latest

Reporting a Vulnerability

We take the security of pleezer seriously. If you discover a security vulnerability, please follow these steps:

  1. Do not report security vulnerabilities through public GitHub issues or discussions
  2. Contact the author directly via email (see Contacting the Author)
  3. Include detailed steps to reproduce the vulnerability
  4. Wait for acknowledgment before any public disclosure

What to Expect

  • Acknowledgment: We aim to acknowledge reports within a few days to a few weeks
  • Updates: We will keep you informed of our progress
  • Disclosure: We will coordinate the public disclosure with you after the fix is released
  • Credit: We will acknowledge your contribution in the release notes (unless you prefer not to be credited)

Security Practices

For Users

  • Keep your secrets.toml file secure and private
  • Update to the latest version of pleezer regularly
  • Use strong, unique passwords for your Deezer account
  • Avoid sharing sensitive information in public forums

For Contributors

We maintain security through:

  • Weekly dependency scans via GitHub Dependabot
  • Mandatory code reviews for all changes
  • Security-focused testing and review processes

Security Updates

When we fix a security vulnerability:

  1. We release an update as quickly as possible
  2. We document the fix in the release notes
  3. We notify affected users if necessary

Responsible Disclosure

We kindly request:

  1. Private disclosure of vulnerabilities
  2. Reasonable time to investigate and fix issues
  3. Coordination on public disclosure timing

Your help in keeping pleezer users secure is greatly appreciated.

Questions or Suggestions?

For general security suggestions, use GitHub Discussions. For sensitive security matters, contact the author directly.