If you discover a security vulnerability in Deckboy, please do not open a public GitHub issue.
Instead, report it privately through one of these channels:
- GitHub Security Advisories — use the "Report a vulnerability" button on the Security tab of this repository.
- Email — contact the maintainers through the email listed on the Utopian-Academy organisation profile.
We will acknowledge your report within 48 hours and aim to provide a fix or mitigation within 7 days for critical issues.
Deckboy is a desktop application that is deliberately network-active (NDI, OSC, SRT, RTMP, NMOS, Companion, etc.). Security reports related to any of the following are in scope:
- Remote code execution via crafted media files or network input
- Buffer overflows or memory corruption in the native code
- Vulnerabilities in bundled dependencies (FFmpeg, SDL3, etc.)
- Unintended data exfiltration (Deckboy collects no telemetry by design)
| Version | Supported |
|---|---|
| Latest release | ✅ |
| Older releases | Best effort |
We appreciate responsible disclosure and will credit reporters in the release notes (unless you prefer to remain anonymous).