Release Label Tools 0.1.0
This commit is contained in:
@@ -0,0 +1,14 @@
|
||||
# Security
|
||||
|
||||
Report vulnerabilities privately through the repository owner on the Gitea
|
||||
instance. Do not attach confidential merge data to a public issue.
|
||||
|
||||
Label Tools keeps data in browser memory and accepts only bounded CSV/JSON and
|
||||
PNG/JPEG/WebP assets. Merge text and SVG attributes are escaped. Generated
|
||||
barcode markup comes from a pinned local encoder and is checked for active or
|
||||
linked elements. Remote image URLs, user-provided SVG and arbitrary templates
|
||||
are not accepted in v0.1.
|
||||
|
||||
Generated labels can contain sensitive or guessable identifiers. Review the
|
||||
preview and warnings before export, and do not treat serial/random values as an
|
||||
access-control system without an independent security design.
|
||||
Reference in New Issue
Block a user