Skip to content

Security: 96886/MusicPlaylistApp

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest main branch receives security updates.

Reporting a Vulnerability

If you discover a security vulnerability in Wavely, please do not open a public issue.

Instead, report it privately by:

  1. Opening a GitHub Security Advisory, or
  2. Emailing the maintainers directly.

Please include:

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested mitigation

We aim to acknowledge reports within 72 hours and provide a fix or mitigation within 30 days depending on severity.

Scope

Wavely is a client-side demo app. Local audio files are held in-memory via URL.createObjectURL() and never uploaded. Reports about third-party sample audio (SoundHelix) are out of scope.

There aren't any published security advisories