Skip to content

Latest commit

 

History

History
49 lines (34 loc) · 1.42 KB

File metadata and controls

49 lines (34 loc) · 1.42 KB

Security Policy

Supported Versions

Version Supported
1.x

Reporting a Vulnerability

If you discover a security vulnerability in NullPlayer, please report it responsibly:

  1. Do not open a public GitHub issue for security vulnerabilities
  2. Email the maintainer directly or use GitHub's private vulnerability reporting
  3. Include as much detail as possible:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Any suggested fixes (optional)

What to Expect

  • Acknowledgment: We will acknowledge receipt of your report within 48 hours
  • Assessment: We will assess the vulnerability and determine its severity
  • Fix Timeline: Critical issues will be addressed as quickly as possible
  • Disclosure: We will coordinate with you on public disclosure timing

Scope

This security policy covers:

  • The NullPlayer application code
  • Build and bootstrap scripts
  • Any bundled dependencies

This policy does not cover:

  • Third-party services (Plex, Sonos, etc.)
  • User-installed skins or presets
  • Upstream dependencies (report to those projects directly)

Security Best Practices for Users

  • Download NullPlayer only from official sources
  • Keep your macOS system updated
  • Be cautious with skins from untrusted sources
  • Use strong Plex account credentials

Thank you for helping keep NullPlayer secure!