Skip to content

Security: olong75/echoquell

Security

SECURITY.md

Security Policy

Supported versions

echoquell is pre-1.0; only the latest released version on the main branch receives fixes.

Version Supported
0.3.x
< 0.3

Reporting a vulnerability

echoquell is an offline signal-processing library — it does not open sockets, run a server, or execute untrusted input — so the attack surface is small. Still, if you find something (for example a way to trigger a crash or excessive memory use from a crafted WAV file), please report it privately.

Use GitHub's Report a vulnerability button under the Security tab, or open a minimal issue without exploit details and I will follow up. I aim to acknowledge reports within a week.

Please do not disclose publicly until a fix is released.

There aren't any published security advisories