Skip to content

Security: TheGeneCode/MeadowLark

SECURITY.md

Security Policy

MeadowLark handles sensitive data locally — browser session cookies (cookies.txt), YouTube authentication used for "mark watched," and PO tokens used to unlock downloads. Please treat any vulnerability that could leak, misuse, or escalate access via this data as high priority.

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Instead, use GitHub's private vulnerability reporting:

  1. Go to the Security tab of this repository.
  2. Click Report a vulnerability.
  3. Describe the issue, steps to reproduce, and potential impact.

You should get an acknowledgment within a few days. Confirmed issues will be prioritized for a fix and you'll be credited in the release notes, unless you'd rather stay anonymous.

Supported Versions

Only the latest released version receives security fixes. Please confirm you're on the newest release (see Releases) before reporting.

There aren't any published security advisories