Skip to content

Security: KanadeK/shadowbricks

Security

SECURITY.md

Security policy

Supported versions

The latest tagged release receives security fixes. Pre-release branches and generated example artifacts are not separate supported products.

Reporting a vulnerability

Please use the repository's Security → Report a vulnerability flow to open a private GitHub security advisory. Do not include secrets, private models, or exploit details in a public issue.

Include the affected version, operating system, input type, minimal reproduction, and expected impact. You should receive an acknowledgement within seven days.

Runtime boundary

Shadowbricks is local-first. It performs no runtime network requests, starts no server, executes no content from input files, and stores no credentials. Raster images and JSON files are untrusted boundary inputs; generated HTML contains no JavaScript.

There aren't any published security advisories