Skip to content

Security: jfleezy23/frame-player

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not open a public GitHub issue for suspected security vulnerabilities.

For sensitive reports:

  • use GitHub's private vulnerability reporting for this repository
  • otherwise contact the maintainer directly through GitHub: jfleezy23

When reporting an issue, include:

  • a short description of the problem
  • affected version or release tag
  • reproduction steps or proof-of-concept details
  • any known impact or mitigation notes

Current Screening and Guardrails

This repository currently uses a mix of GitHub-native security tooling and workflow guardrails to reduce drift and catch issues earlier:

  • main requires pull requests before merge, including for administrators.
  • Branch protection currently requires the CodeQL analyses for Actions, C#, and Rust; dependency review; macOS and Windows build-and-test; and SonarQube analysis before merge.
  • Merged branches are deleted automatically to reduce branch sprawl and stale release drift.
  • Windows CI runs on pushes and pull requests and verifies pinned runtime restore, the universal Release build, tests, and packaging.
  • The repository CodeQL workflow analyzes actions, csharp, and rust.
  • GitHub secret scanning is enabled to detect known leaked secret patterns in repository history.
  • GitHub push protection is enabled to block many secrets before they are pushed.
  • The dependency graph and automatic dependency submission are enabled so GitHub can reason about shipped dependencies beyond just manifest files.
  • Dependabot security and version update pull requests are enabled for NuGet, Cargo, and GitHub Actions dependencies.
  • Dependency review now runs on pull requests to flag newly introduced vulnerable dependencies before merge.
  • NuGet restore audits direct and transitive packages at moderate severity or higher, and CI treats audit warnings as errors.
  • Release packaging artifacts can be attested with GitHub artifact attestations so published build provenance can be verified.
  • A SonarQube Cloud workflow is configured for PRs and main pushes, and becomes active when the repository SONAR_TOKEN secret is present; repository-level overrides are available for organization and project key if the default mapping is not correct.
  • The macOS workflow builds and tests the same Avalonia project and verifies its application bundle. Release-candidate corpus validation remains a local/manual gate because the corpus is not stored in git.
  • The required Windows CI job enforces Roslyn analysis and naming rules, warning-free builds, C# and Rust formatting, Rust Clippy, PowerShell analysis, ShellCheck, workflow validation, spelling, and repository path/text casing.
  • GitHub Actions used by repository workflows must be pinned to full commit SHAs.
  • Pull request templates and issue templates are in place to keep validation, documentation, and security review visible during review.

These checks improve detection and consistency, but they are not a guarantee that a release is free of vulnerabilities. Human review and release validation still matter.

Runtime Network Posture

Frame Player is designed as a local review tool. The universal application does not include telemetry, analytics, auto-update, HTTP client, socket, or background network-service code. It uses local media files, bundled FFmpeg libraries, per-user local state, and a hidden local child process for export and export-side probe work on both supported platforms.

The bundled playback and export runtimes are built with FFmpeg networking disabled. Runtime manifests record their pinned source provenance and expected SHA-256 values; the export host validates its bundled native libraries before configuring them, and release validation checks the packaged runtime hashes. Export filenames are bound through FFmpeg options rather than interpolated into filtergraph text. Recent-file records and diagnostic logs stay in the current user's profile and are not transmitted by the application.

Repository build and developer workflows can perform outbound network access for NuGet restore, HTTPS downloads of pinned FFmpeg runtime artifacts, optional official FFmpeg source clones, and optional signing timestamp requests. Those are build-time supply-chain paths, not runtime telemetry paths. Network-restricted review builds should restore NuGet packages from an approved local cache/feed, stage the required runtime folders locally, and build with -p:SkipRuntimeBootstrap=true.

macOS Signing And Notarization Expectations

  • Public macOS distribution requires a Developer ID Application certificate, hardened runtime signing, notarization, stapling, and Gatekeeper validation of the final archived artifact after extraction.
  • The current required entitlement is com.apple.security.cs.allow-jit for .NET. Do not add entitlements unless a concrete runtime failure proves they are required.

Scope and Background

Maintainer-facing workflow and branch-protection expectations are documented in docs/security-quality-baseline.md.

Disclosure Expectations

  • Please give the maintainer a reasonable opportunity to investigate and remediate before public disclosure.
  • Non-sensitive bugs and hardening suggestions can still be opened as normal GitHub issues.

There aren't any published security advisories