Only the latest main branch receives security updates.
If you discover a security vulnerability in Wavely, please do not open a public issue.
Instead, report it privately by:
- Opening a GitHub Security Advisory, or
- Emailing the maintainers directly.
Please include:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested mitigation
We aim to acknowledge reports within 72 hours and provide a fix or mitigation within 30 days depending on severity.
Wavely is a client-side demo app. Local audio files are held in-memory via URL.createObjectURL() and never uploaded. Reports about third-party sample audio (SoundHelix) are out of scope.