We are committed to keeping ReLink secure.
At this time, we only provide security updates and patches for the latest stable releases.
If you are using an outdated version of the library, we strongly recommend upgrading to the most recent version to ensure you have the latest security fixes and type-checking improvements.
Please do not report security vulnerabilities through public GitHub issues.
If you discover a potential security flaw in ReLink (e.g., sensitive data leakage, improper payload handling, or crashing vulnerabilities), please report it via one of the following methods:
- GitHub Security Advisory: Navigate to the Security tab of this repository and select "Report a vulnerability". This is the preferred method as it allows for a private discussion, collaborative fixing, and a formal CVE assignment if necessary.
- Private Contact: You may contact the lead maintainer directly on our Discord Server.
Once a report is received:
- We will acknowledge the report within 48 hours.
- We will work on a fix in a private, secure environment.
- A security advisory and a patched version will be published simultaneously to notify the community.
We ask that you do not disclose the vulnerability publicly until a fix has been released. This helps protect the community and users who rely on ReLink for their production audio systems.