DU (渡) is a client-side only application: there is no backend, no API, no third-party analytics, and no LLM. All computation happens in your browser. This document is bilingual: English first, then 中文.
| Version | Support |
|---|---|
| 1.x | ✅ Active |
Please do not open a public GitHub Issue for security problems. Use one of these private channels:
- GitHub Security Advisories (preferred): https://github.com/badhope/DU/security/advisories/new
- Email the maintainer: see the contact on the README.md profile section
You should receive an acknowledgement within 72 hours. We will coordinate a fix, a CVE if applicable, and a public advisory after the patch is released.
如发现安全问题,请不要通过公开 Issue 报告。私有渠道:
- GitHub Security Advisories(推荐):https://github.com/badhope/DU/security/advisories/new
- 邮件联系维护者:见 README.md 末尾
我们会在 72 小时内响应,并与您协调修复、申请 CVE(如适用),修复发布后发布公开公告。
- gitleaks runs on every
pushand every PR, plus a daily scheduled scan. Leaks fail the build. - CodeQL (
javascript-typescript) runs on a weekly schedule + every push tomain. - Dependency audit —
pnpm audit --prod --audit-level=highblocks the CI build if any high-severity issue is present in production dependencies. - Dependency overrides force
jpeg-js@^0.4.4and@intlify/{core-base,message-resolver}@^9.1.11, neutralizing transitive CVEs shipped inside uni-app's bundle. - Branch protection —
enforce_admins: true, status checks required, no force-push, linear history, squash merge only. - Type safety — TypeScript
strictmode +vue-tsctype check at build time.
- All divination data, profiles, achievements, and chat history are stored in your browser's
localStorageunder the keydu-state-v1. - Nothing is uploaded to any server. The app makes no
fetch,XMLHttpRequest, oruni.requestcalls. This is verified bygrepin CI. - No third-party SDKs are bundled — no Google Analytics, no Sentry, no Umeng, no Baidu Tongji, no AdSense.
- You can wipe your data at any time from Settings → Privacy → Clear all data.
- 所有占卜数据、个人档案、成就、聊天记录都存于浏览器
localStorage(key:du-state-v1)。 - 不向任何服务器上传。本应用无
fetch/XMLHttpRequest/uni.request调用,CI 中用grep校验。 - 不集成任何第三方 SDK — 无 Google Analytics、无 Sentry、无 Umeng、无百度统计、无 AdSense。
- 可随时在 设置 → 隐私 → 清除全部数据 中清空。
| Threat | Risk | Why |
|---|---|---|
| Server-side data breach | None | There is no server |
| XSS via user input | Low | No v-html / innerHTML / eval / new Function; Vue text interpolation is safe by default |
| CSRF / session hijacking | None | No cookies, no auth, no server |
| Tracking / fingerprinting | None | No analytics SDKs, no CDN with cookies |
| Malicious dependency update | Low | pnpm audit + pnpm.overrides for known-bad transitive deps |
| Supply-chain via lockfile | Low | pnpm install --frozen-lockfile in CI |
| Local privilege escalation | N/A | No native code, no shell, no nodeIntegration |
- Issues in uni-app x, Vue 3, Pinia, GSAP, Vite, or other upstream dependencies → please report upstream.
- Cultural / factual accuracy of divination results → these are heuristic and educational, not authoritative.
- Output of the in-browser "AI Masters" — they are rule-based and intentionally simplistic.