Security policy
Supported versions and the private channel for reporting a vulnerability.
Security fixes target the latest 0.1.x release and the current main branch. Older releases, other branches and forks are not supported; the deleted historical v1.0.0 tag must not be recreated.
Reporting
Use the product repository's private vulnerability reporting form.
If private reporting is unavailable, open a minimal public issue asking for a private contact channel. Do not include sample media, exploit code, credentials, or other sensitive details in that issue.
Include the affected commit or image tag, clear reproduction steps, the expected impact, and a sanitized proof of concept when possible. You should receive an acknowledgement within seven days and an initial assessment within fourteen days.
Relevant scope
- user media leaving the browser, or any new upload path;
- npm dependency supply chain;
- Docker image and Nginx;
- GitHub Actions workflows;
- HTTP headers, especially COOP/COEP/CSP;
- browser surface: blobs and WASM.
The authoritative text remains SECURITY.md.