This is a client-side web app deployed continuously from main. Only the
currently deployed version receives fixes.
Please report security issues privately, not in public issues. Use GitHub's "Report a vulnerability" button under the repository's Security tab.
Include the affected page/feature, a description and impact, and steps to reproduce or a proof of concept.
This is a small, best-effort project, so please allow some time for a response before any public disclosure.
In scope: the web app in this repository (HTML/CSS/JS) and the GitHub Actions workflows.
Out of scope: Vintage Story itself and the dedicated-server Docker image that consumes the generated tokens — report those in their respective projects.