Thank you for reporting security vulnerabilities responsibly before any public disclosure.
WaveFlow for Android does not have long-term version support yet. The main branch and the latest published release should be considered the only supported versions for security fixes.
| Version | Supported |
|---|---|
main / latest published release |
Yes |
| Older versions, snapshots, and unmaintained forks | No |
Do not open a public issue for security vulnerabilities.
Use one of these channels, depending on what is available on the public repository:
- GitHub Security Advisories: open the repository's Security tab, then choose Report a vulnerability. This is the recommended confidential channel.
- Contact the maintainers privately if GitHub Security Advisories are not available.
Your report should include:
- the affected version (or commit) and the Android version you ran it on;
- a description of the vulnerability and its impact;
- reproduction steps, and a sample file if the issue is triggered by one;
- any suggested fix, if you have one.
Please allow a reasonable delay for a fix before public disclosure.
Things that are in scope for this repository:
- reading and parsing audio files surfaced through
MediaStore— malformed or hostile tags, artwork, and container structures; - anything that could let a file or intent escape the app's scoped storage or read/overwrite data outside the app's own storage;
- exported components (activities, services, receivers, providers) and the intents they accept;
- the future WaveFlow server sync (signed URLs, credential handling) once it lands.
Out of scope:
- vulnerabilities in Android itself or in vendor OS builds (report those to the respective vendor);
- issues that require a rooted device, a hostile ADB session, or physical access to an unlocked phone;
- the desktop and iOS clients — report those on their own repositories.