Skip to content

Security: cromaguy/Rhythm

Security

SECURITY.md

Security Policy

Supported Versions

We take security seriously. This section outlines which versions of Rhythm are currently supported with security updates.

Version Supported
3.7.x
3.6.x
< 3.6

Reporting a Vulnerability

If you discover a security vulnerability in Rhythm, please help us by reporting it responsibly.

How to Report

Please do NOT report security vulnerabilities through public GitHub issues.

Instead, please report security vulnerabilities by emailing:

What to Include

When reporting a security vulnerability, please include:

  1. Description: A clear description of the vulnerability
  2. Steps to Reproduce: Detailed steps to reproduce the issue
  3. Impact: Potential impact and severity of the vulnerability
  4. Affected Versions: Which versions are affected
  5. Environment: Android version, device information
  6. Proof of Concept: If possible, include a proof of concept

Our Response Process

  1. Acknowledgment: We will acknowledge receipt of your report within 48 hours
  2. Investigation: We will investigate the report and determine its validity
  3. Updates: We will provide regular updates on our progress (at least weekly)
  4. Fix: If valid, we will work on a fix and coordinate disclosure
  5. Disclosure: We will publicly disclose the vulnerability after a fix is available

Responsible Disclosure

We kindly ask that you:

  • Give us reasonable time to fix the issue before public disclosure
  • Avoid accessing or modifying user data
  • Do not perform DoS attacks or degrade the service
  • Do not spam our systems with automated tools

Recognition

We appreciate security researchers who help keep our users safe. With your permission, we may publicly acknowledge your contribution to our security.

Contact

For security-related questions or concerns:

Thank you for helping keep Rhythm and its users secure! 🛡️

There aren’t any published security advisories