Report a vulnerability
This page is the reporting channel for security vulnerabilities in Truffle and on this website — in the sense of the EU Cyber Resilience Act. It says where a report goes, what helps, and what you can expect from us afterwards. The German version is authoritative; this English text is provided for convenience.
Contact: security@truffle-app.com
Please do not file public bug reports for security-relevant findings. A publicly described flaw can be used by anyone from the moment it is published — including those who never intended to report it.
What helps in a report
- What happens, and what you expected instead
- The steps that reproduce it
- Your Truffle version and macOS version
- Whether you were working with Apple Music, with local folders, or with a rekordbox collection
A proof that the flaw can be exploited is welcome but not required. A report with gaps is better than no report.
What you can expect
- Acknowledgement within five working days.
- Initial assessment within ten working days — whether it reproduces and how severe it is.
- A corrected version according to severity; for actively exploitable flaws as fast as a build and Apple's notarisation take.
- A reply in every case — even if we do not classify the finding as a vulnerability, then with reasons.
Anyone who reports a vulnerability and gives us time to fix it will be credited in the release notes on request. Anyone who prefers to remain unnamed remains unnamed.
How a fix reaches you
A corrected, signed and Apple-notarised version is made available at
download.truffle-app.com; reporters are notified. Truffle learns of it in two ways:
it checks at launch and once a day, via the Sparkle update module, whether a new version is
available, and the licence server names the current version to activated installations with
every confirmation. In both cases Truffle shows you the update — it is downloaded and
installed only once you confirm it. Until then the old version keeps running. For an
actively exploited flaw the licence server can additionally retire older versions as a minimum
version; activated installations then see the notice at least 30 days in advance (see the
licence agreement, section 4).
Support period
The support period within the meaning of the EU Cyber Resilience Act is five years from the day a version was last offered for download, and applies from version 1.0 onwards. During this period reported vulnerabilities are handled within the time frames stated above and fixed versions are made available for download. Truffle is maintained as one line: security fixes are issued for the current version, older releases receive no backports — and the current version runs on the same systems as the one it replaces.
What Truffle does — and does not do
This belongs here because it describes the attack surface:
- No account, but a licence server. There is nothing to sign in to. Activated installations talk regularly to
lizenz.truffle-app.com(activation, confirmation about every 30 minutes, device limit); what is transmitted is the hash of the licence key, a device key generated by Truffle, the computer name, version, build, architecture, the hash of the running program code and an integrity status — nothing about your music. The full list is in section 4 of the privacy notice. The server is part of the product and of this policy — reports concerning it are accepted through the same channel. The demo version makes no contact with the licence server. - Public catalogues are queried, plus Apple's audio recognition — without keys, without sign-in. What is transmitted is what is searched for: title, artist, album.
- Writing goes exclusively into your library — into Music.app via AppleScript, into local files via TagLib. Every change passes through a safety net it can be recovered from.
- Truffle executes no code you have not confirmed. The update check loads only a small, signed description file; an update itself is downloaded only after your confirmation, is signed by us and notarised by Apple, and is verified twice before installation. If the licence server is down, Truffle additionally fetches an emergency document signed by us (grace extension, certificate pins) — never code.
- The app does not run in the sandbox, because it must access folders of your choosing and Music.app. macOS asks you for both.
A software bill of materials listing the bundled third-party components exists and is provided on request to the same address.
As of 29 August 2026