Please report security issues privately through the repository's GitHub security advisory feature. Do not include secrets, credentials, private media URLs, or downloaded content in a public issue.
Security-sensitive areas include process execution, URL validation, destination bookmarks, temporary-file handling, dependency integrity, update manifests, and the bundled yt-dlp, FFmpeg, LAME, and Deno artifacts.
Videos never constructs shell commands from user input. Source URLs are passed as individual process arguments after an option separator.