| Version | Supported |
|---|---|
| 0.1.x | Yes |
Please report security issues privately — do not open a public GitHub issue for exploitable flaws.
- Prefer GitHub private vulnerability advisories on this repository, or
- Email the maintainer listed in
package.json(author) with a description, impact, and reproduction steps.
We aim to acknowledge reports within 7 days and to ship a fix or mitigation for confirmed issues as soon as practical. There is no bug bounty program at this time.
This package is a media player (speech queue + optional ambient). Reports related to:
- Privilege escalation via the config plugin / FGS declaration
- Session / notification spoofing that affects other apps
- Unsafe URL handling that leads to unexpected native code execution
…are in scope. Issues that only affect app-level product policy (e.g. RemoteNext mapping) belong in normal issues.