Files
privacy-tools/SECURITY.md
T
2026-09-01 02:39:44 +02:00

1.6 KiB

Security

Report vulnerabilities privately to the repository owner. Do not attach a sensitive source image, generated report, or real metadata to a public issue; construct a minimal synthetic reproduction instead.

Input model

Every selected file and every metadata value is untrusted. The application detects containers from bytes, does not execute imported content, renders text through React rather than raw HTML, performs no metadata-linked fetches, and does not preserve source blocks in a re-encoded output. The scanning worker can be terminated on cancellation. Browser-native pixel decoding remains part of the browser's trusted computing base.

Default bounds cover file/batch bytes, container blocks, individual metadata, decompressed PNG metadata, finding lengths/counts, TIFF offsets/entries/depth, pixel count/edge, and batch ZIP size. Malformed structures become partial or failed coverage; they must never receive clean-copy eligibility or a verified output result.

Output model

A successful Canvas encode is not sufficient. The new bytes are independently hashed and scanned, expected oriented dimensions are checked, sensitive or provenance findings fail the verification gate, and incomplete coverage is reported. C2PA/JUMBF signatures are expected to be removed or invalidated by pixel re-encoding. Reports and output names are escaped/sanitized and ZIP paths are application-generated.

No status is an anonymity guarantee. Visible content, steganography, invisible watermarks, image fingerprinting, sidecars, local filesystem metadata, browser history, and remote copies are outside the scan.