Skip to content

Security: SonyDew/SonyDev-Bypass

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Do not post secrets, tokens, private endpoints, or vulnerability details in a public issue.

If the issue affects the official SonyDev infrastructure or official binaries, use a private reporting channel first:

  • GitHub security advisories, if enabled for the repository
  • the official contact page: sonydev.de/contact

Scope

The public repository does not include production secrets. If you find:

  • hardcoded credentials
  • infrastructure tokens
  • unsafe update behavior
  • path traversal or arbitrary file write issues
  • installer privilege escalation risks

report them privately before disclosure.

This file is a project policy note, not legal advice.

There aren't any published security advisories