Skip to content

Security: DevMatei/make-a-wrapped

SECURITY.md

Security Policy

Reporting a Vulnerability

Found a security issue in Make a Wrapped? Please report it privately so we can fix it before it becomes public.

Do not open a public issue, PR, or forum post about a vulnerability before we've had a chance to assess and fix it. Responsible disclosure helps everyone.

What to Include

A good report is short but complete. Please share:

  • The affected URL, endpoint, or component.
  • A step by step way to reproduce it.
  • The impact (what an attacker could gain).
  • Any proof of concept, screenshots, or logs (optional).
  • Your preferred way to be credited in the acknowledgements, if any.

If you found a data leak, auth bypass, injection, or anything that could put a user's data or credentials at risk, that counts. Even if you're not sure, send it our way.

Supported Versions

Only the latest release is actively maintained for security fixes. Older versions and unreleased builds (like the experimental Navidrome Native API mode) are not guaranteed to receive patches.

Version Supported
Latest release Yes
Older releases No
master / unreleased features No, use at your own risk

Response

We'll acknowledge your report as soon as we can, usually within a few days. We'll keep you updated on the fix and, once it ships, let you know on the changelog. If you want public credit, we're happy to add you to the acknowledgements.

Scope

Make a Wrapped is a small open source project. Your credentials never leave your browser when using Navidrome, and the server only stores essential data for badges and artwork. If you're unsure whether something is in scope, report it anyway.

Learn more about advisories related to DevMatei/make-a-wrapped in the GitHub Advisory Database