| Version | Supported |
|---|---|
| 1.x | ✅ |
If you discover a security vulnerability in NullPlayer, please report it responsibly:
- Do not open a public GitHub issue for security vulnerabilities
- Email the maintainer directly or use GitHub's private vulnerability reporting
- Include as much detail as possible:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes (optional)
- Acknowledgment: We will acknowledge receipt of your report within 48 hours
- Assessment: We will assess the vulnerability and determine its severity
- Fix Timeline: Critical issues will be addressed as quickly as possible
- Disclosure: We will coordinate with you on public disclosure timing
This security policy covers:
- The NullPlayer application code
- Build and bootstrap scripts
- Any bundled dependencies
This policy does not cover:
- Third-party services (Plex, Sonos, etc.)
- User-installed skins or presets
- Upstream dependencies (report to those projects directly)
- Download NullPlayer only from official sources
- Keep your macOS system updated
- Be cautious with skins from untrusted sources
- Use strong Plex account credentials
Thank you for helping keep NullPlayer secure!