Skip to content

Security: Kumpelo/muscli

Security

SECURITY.md

Security policy

Supported versions

Security fixes are provided for the latest published prerelease or stable release. Development snapshots are supported on a best-effort basis.

Reporting a vulnerability

Please use GitHub's private vulnerability reporting for this repository. Do not open a public issue containing an exploit, private path, or user data. Include the affected version, platform, reproduction, impact, and any proposed mitigation. You should receive an acknowledgement within seven days.

muscli does not require network access. Reports involving local IPC, playlist or tag parsing, SQLite migrations, removable-media identity, installer supply chain, and child-process execution are in scope.

There aren't any published security advisories