Skip to content

Security: Cameudis/SWOTS

SECURITY.md

Security

Only the latest release and development branch are supported.

Report code execution, privilege expansion, crashes, data corruption, or malicious packages privately through the host's Security → Report a vulnerability feature. If unavailable, ask a maintainer for a private channel before sending details. Include the version/commit, HOS, Atmosphère, Tesla, nx-ovlloader, impact, prerequisites, and minimal reproduction. Allow up to seven days for acknowledgement.

Never send keys, game content, personal data, or SD card images.

SWOTS uses privileged VI, HID, and PM services and broad legacy-compatible NPDM permissions. It is not sandboxed. Install only trusted builds and verify the published hash.

SWOTS collects no telemetry. Settings and diagnostic logs remain under /config/swots/.

There aren't any published security advisories