Please do not report security vulnerabilities through public GitHub issues.
If you believe you've found a security issue in Deemix Remastered, report it privately so we can investigate and ship a fix before details become public.
The preferred channel is GitHub's private vulnerability reporting:
This creates an issue that's only visible to the maintainers and to you, with a built-in workflow for coordinating a fix and a CVE if applicable.
- A description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce the issue
- The app version, your operating system, and any relevant configuration
- A suggested fix or mitigation (if you have one)
- Whether you'd like to be credited in the advisory once it's published
- Acknowledgement: within 7 days
- Initial assessment: within 14 days
- Coordinated disclosure: we'll work with you on a timeline before publishing details
We'll keep you updated as the investigation progresses, and we'll credit you in the advisory and release notes unless you'd rather stay anonymous.
Only the latest released version receives security fixes. Older versions may continue to work but will not be patched. Please update to the latest release before reporting.
| Version | Supported |
|---|---|
| 1.5.x | ✅ |
| < 1.5 | ❌ |
The following are not in scope for this policy:
- Issues affecting the Deezer or Spotify upstream services themselves
- Vulnerabilities in third-party software the app depends on (please report those upstream)
- Reports that require physical access to an unlocked device the user is already signed in on
- Reports about the legality or terms-of-service compliance of music downloading itself — see the disclaimer in the README