Please do not open a public GitHub issue for security vulnerabilities.
Report them privately by email to the maintainer at [email protected]. Include:
- the affected package version
- a description of the vulnerability
- steps to reproduce (if available)
- any proof-of-concept code
You will receive an acknowledgment within 5 business days, and a fix will be coordinated before the vulnerability is disclosed publicly.
This policy covers the ytdlp-react-native package and its example application.
The embedded third-party components (yt-dlp-android, yt-dlp, Chaquopy,
Python) have their own security policies and distribution channels.
- Do not use this library to access unauthorized or private content.
- Do not use this library to circumvent DRM or authentication.
- Never share cookies, authorization headers, or private URLs in public issues.
| Version | Supported |
|---|---|
| 0.1.x | Yes |