Skip to content

Latest commit

 

History

History
21 lines (14 loc) · 697 Bytes

File metadata and controls

21 lines (14 loc) · 697 Bytes

Security Policy

Supported versions

Security fixes are applied to the latest minor release.

Reporting a vulnerability

Open a private security advisory on GitHub, or email the maintainer listed in the package metadata.

Security model

Webring Kit intentionally does not execute code from ring manifests.

  • Ring JSON is treated as untrusted input.
  • URLs are validated and restricted to http: and https:.
  • Site titles and descriptions are rendered with textContent, never innerHTML.
  • _blank links use rel="noopener noreferrer".
  • The widget does not set cookies.
  • localStorage caching is opt-in.
  • The CLI can verify reciprocal links and well-known ownership files.