Skip to content

Security: bwb-tools/render-viewer

SECURITY.md

Security policy

Supported versions

Render Compositor is a static site with no server-side code. Only the latest version on main, which is what runs at renderviewer.com, receives fixes.

Reporting a vulnerability

Please don't open a public issue for security problems. Report them privately instead:

  1. Open the repository's Security tab and click Report a vulnerability, or go straight to the report form.
  2. Describe the problem, the steps to reproduce it, and what an attacker could do with it.

Only maintainers can see the report. We'll reply there, and credit you when the fix ships unless you'd rather stay anonymous.

Scope

In scope: anything in the app or the landing page that could harm a visitor. For example, running script through a crafted image or project file, or making the page send a user's images or data anywhere.

Out of scope: problems that need an already-compromised browser or device, and issues in third-party services such as GitHub Pages.

There aren't any published security advisories