Skip to content

Security: weddle/zepp-cloud-sdk

Security

SECURITY.md

Security Policy

We take security seriously and appreciate responsible disclosure.

Supported Versions

The latest released version and the main branch receive security fixes.

Reporting a Vulnerability

  • Do not open public issues for security reports.
  • Please use GitHub Security Advisories (preferred) or contact the maintainers privately.
  • If private contact info is not yet listed, open a minimal issue asking for a security contact method.

Provide as much detail as possible, including reproduction steps and affected versions. We will acknowledge receipt within 72 hours and provide a timeline for remediation where possible.

Tokens and Sensitive Data

  • Never include real apptoken or user identifiers in issues, PRs, or logs.
  • Redact tokens in any diagnostic output.

Cryptography and Dependencies

  • Please flag any high or critical findings.

There aren't any published security advisories