Skip to content

Security: luke-hurd/rondocode

Security

SECURITY.md

Security Policy

rondocode is a client-side web app with no backend; tunes are shared purely via the URL, so there is no server to attack and no user data stored remotely.

Reporting a vulnerability

If you find a security issue (for example, a way for a shared link to run unexpected code beyond the sandboxed audio/visual DSL), please report it privately to me@vijay.io rather than opening a public issue.

Include steps to reproduce and the affected version/commit. You'll get an acknowledgement as soon as possible, and credit in the fix if you'd like it.

There aren't any published security advisories