If you discover a security vulnerability in this project, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
Instead, please email: jediknight112@users.noreply.github.com
- A description of the vulnerability
- Steps to reproduce the issue
- Any potential impact
- You should receive an acknowledgment within 48 hours.
- A fix will be prioritized based on severity.
This policy applies to the tfd-builds web application. The companion tfd-cache service has its own security considerations.
By design, this application exposes API keys to the browser (they are injected into the page at runtime by the Cloudflare Worker). These keys are intended for client-side use and are scoped accordingly. This is not a vulnerability.
Only the latest version deployed on the main branch is supported with security updates.