Security fixes are made on the latest source revision. CloudSound does not publish official binaries or operate an update channel.
Please use GitHub's private vulnerability reporting for this repository when it is available. If it is not enabled, contact the maintainer through the GitHub profile for patrick91 with a non-sensitive request for a private reporting channel.
Do not include real SoundCloud OAuth tokens, cookies, passwords, signing material, or another person's private data in a public issue. Use synthetic values in reproductions and redact logs before sharing them.
Include the affected revision, macOS/Xcode versions, the trust boundary involved, reproduction steps that do not target other users, and the expected safe behavior.
CloudSound is an unofficial source-only client that relies on undocumented SoundCloud web APIs. Breakage caused solely by an upstream API or response-shape change is usually a compatibility issue. Credential exposure, origin confusion, unsafe authenticated network destinations, cross-account state leakage, and sandbox/signing regressions are security-relevant.