Skip to content

Security: DRAZY/deemix-remastered

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

If you believe you've found a security issue in Deemix Remastered, report it privately so we can investigate and ship a fix before details become public.

How to report

The preferred channel is GitHub's private vulnerability reporting:

Open a private security advisory

This creates an issue that's only visible to the maintainers and to you, with a built-in workflow for coordinating a fix and a CVE if applicable.

What to include

  • A description of the vulnerability and its potential impact
  • Step-by-step instructions to reproduce the issue
  • The app version, your operating system, and any relevant configuration
  • A suggested fix or mitigation (if you have one)
  • Whether you'd like to be credited in the advisory once it's published

What to expect

  • Acknowledgement: within 7 days
  • Initial assessment: within 14 days
  • Coordinated disclosure: we'll work with you on a timeline before publishing details

We'll keep you updated as the investigation progresses, and we'll credit you in the advisory and release notes unless you'd rather stay anonymous.

Supported Versions

Only the latest released version receives security fixes. Older versions may continue to work but will not be patched. Please update to the latest release before reporting.

Version Supported
1.5.x
< 1.5

Out of Scope

The following are not in scope for this policy:

  • Issues affecting the Deezer or Spotify upstream services themselves
  • Vulnerabilities in third-party software the app depends on (please report those upstream)
  • Reports that require physical access to an unlocked device the user is already signed in on
  • Reports about the legality or terms-of-service compliance of music downloading itself — see the disclaimer in the README

There aren't any published security advisories