Skip to content

Security: akonopcz/SonicDeck

Security

SECURITY.md

Security Policy

Supported Versions

We release patches for security vulnerabilities in the following versions:

Version Supported
0.8.x
< 0.8

Reporting a Vulnerability

We take the security of SonicDeck seriously. If you believe you have found a security vulnerability, please report it to us as described below.

How to Report

Please do NOT report security vulnerabilities through public GitHub issues.

Instead, please report them via email to: adrikonop@gmail.com

Please include the following information in your report:

  • Type of vulnerability
  • Full paths of source file(s) related to the vulnerability
  • Location of the affected source code (tag/branch/commit or direct URL)
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if possible)
  • Impact of the vulnerability, including how an attacker might exploit it

This information will help us triage your report more quickly.

What to Expect

  • Acknowledgment: We will acknowledge receipt of your vulnerability report within 48 hours.
  • Investigation: We will investigate the issue and determine its impact and severity.
  • Updates: We will keep you informed about our progress toward fixing the vulnerability.
  • Fix Timeline: We aim to release a fix within 30 days for critical vulnerabilities.
  • Credit: If you desire, we will publicly acknowledge your responsible disclosure once the vulnerability is fixed.

Security Best Practices

When using SonicDeck, we recommend:

  • Keep your installation up to date with the latest version
  • Only download SonicDeck from official sources (GitHub Releases)
  • Review the permissions requested by the application
  • Be cautious when importing sound libraries from untrusted sources
  • Keep your operating system and dependencies updated

Disclosure Policy

  • We will confirm the vulnerability and determine its impact
  • We will release a fix as soon as possible, depending on the complexity
  • We will publish a security advisory on GitHub after the fix is released
  • We will credit the reporter (unless they prefer to remain anonymous)

Comments on this Policy

If you have suggestions on how this process could be improved, please submit a pull request or open an issue.

There aren't any published security advisories