v0.3.2
This commit is contained in:
@@ -0,0 +1,5 @@
|
||||
# Security policy
|
||||
|
||||
Please report security issues privately to the repository owner rather than opening a public issue containing exploit details.
|
||||
|
||||
SlopDetect treats webpage content, resource URLs, metadata, and provenance manifests as untrusted input. The implementation bounds asset size and concurrency, rejects unsafe URL schemes and cross-origin private-network targets, omits credentials from media requests, disallows redirects, validates extension messages, and renders page annotations through an isolated Shadow DOM without injecting untrusted HTML.
|
||||
Reference in New Issue
Block a user