Skip to content

Security: andresleecom/sonosctl

Security

SECURITY.md

Security Policy

Supported Versions

This project is currently in active development. Security fixes are applied to the latest main branch and most recent release.

Reporting a Vulnerability

Please do not open public GitHub issues for security vulnerabilities.

Report privately by contacting the maintainer:

Include the following details:

  • Affected version/commit
  • Steps to reproduce
  • Expected vs actual behavior
  • Potential impact
  • Suggested remediation (if available)

Response Targets

  • Initial acknowledgment: within 72 hours
  • Triage decision: within 7 days
  • Fix timeline: depends on severity and complexity

Disclosure Policy

  • Vulnerabilities are handled privately until a fix is available.
  • After release of a fix, a public advisory/changelog note may be published.

Scope Notes

  • This CLI controls devices on a local network.
  • Do not include private tokens, credentials, or sensitive logs in reports.

There aren't any published security advisories