Skip to content

Security: patrick91/soundcloud-app

Security

SECURITY.md

Security policy

Supported version

Security fixes are made on the latest source revision. CloudSound does not publish official binaries or operate an update channel.

Reporting a vulnerability

Please use GitHub's private vulnerability reporting for this repository when it is available. If it is not enabled, contact the maintainer through the GitHub profile for patrick91 with a non-sensitive request for a private reporting channel.

Do not include real SoundCloud OAuth tokens, cookies, passwords, signing material, or another person's private data in a public issue. Use synthetic values in reproductions and redact logs before sharing them.

Include the affected revision, macOS/Xcode versions, the trust boundary involved, reproduction steps that do not target other users, and the expected safe behavior.

Scope note

CloudSound is an unofficial source-only client that relies on undocumented SoundCloud web APIs. Breakage caused solely by an upstream API or response-shape change is usually a compatibility issue. Credential exposure, origin confusion, unsafe authenticated network destinations, cross-account state leakage, and sandbox/signing regressions are security-relevant.

There aren't any published security advisories