Skip to content

Security: DomazinUS/Switify

SECURITY.md

Security

Switify stores Spotify reusable authentication credentials locally at sdmc:/config/Switify/credentials.json. Never attach that file to an issue or commit it to a repository. Runtime logs can contain account identifiers and should be reviewed before sharing.

Report a suspected credential exposure or security issue through GitHub's private vulnerability-reporting form under this repository's Security tab. Do not open a public issue first. Revoke exposed Spotify sessions from the Spotify account page and remove the local credentials file.

Switify does not require a Spotify developer client secret and no private key, token, or credential belongs in the source tree.

There aren't any published security advisories