Skip to content

Security: AakashKakkar/avatar-builder

Security

SECURITY.md

Security policy

Supported version

Security fixes are applied to the latest commit on main.

Report a vulnerability

Please use GitHub’s private vulnerability reporting feature for this repository. Do not open a public issue for an undisclosed vulnerability.

Include:

  • affected endpoint or component;
  • reproduction steps;
  • expected impact;
  • suggested mitigation, if known.

The maintainers will acknowledge a complete report as soon as practical and coordinate disclosure after a fix is available.

Scope notes

The public renderer accepts only catalog part identifiers and a validated color. It does not intentionally accept user-supplied SVG, filesystem paths, or remote URLs.

There aren't any published security advisories