Only the latest release line receives security fixes. lattice --version
prints what you are running; PyPI's latest matches main.
Use GitHub's private vulnerability reporting (Security → Report a vulnerability on this repository) rather than a public issue. You should hear back within a week.
- lattice-music is a local, offline tool: it reads the audio files you point
it at and writes reports next to your cwd (or into the library only via the
explicit
--clean/--apestripwrite modes, which are dry-run by default). - The integrity modes shell out to
flac/ffmpegbinaries found onPATH(or an explicit--ffmpegpath). The companion scripts inscripts/shell out toffmpeg/rsgainthe same way and, unlike the package, modify files in place. - Smart-playlist rules are evaluated by a whitelisted AST walker, never by
eval; attribute access, calls, and subscripts in a rule are rejected. - No network access, no telemetry, no auto-updates anywhere in the package.
(The
slipcover.pycompanion queries the iTunes API for missing covers, but that is opt-in via--fetchand lives outside the package.)