Skip to content

Security: Yipxiyi/goose-book

Security

SECURITY.md

Security Policy

Supported Version

Goose Book is pre-1.0 software. Security fixes are shipped on the latest main branch and tagged releases only.

Reporting A Vulnerability

Please report suspected vulnerabilities privately through GitHub Security Advisories when available. If that is unavailable, open a minimal issue that describes the affected surface without publishing exploit details.

Include:

  • affected route or feature
  • reproduction steps
  • expected impact
  • whether credentials, published stories, cloud sync, or public sharing are involved

Security Boundaries

  • Goose Book uses BYOK for LLM providers. User API keys are stored only in the browser and are not included in cloud sync snapshots.
  • Browser-side API key encryption protects against casual local inspection. It is not a defense against XSS, malicious extensions, or code running in the same origin.
  • Supabase sync uses a publishable key. Row access must remain enforced by Supabase Auth and RLS policies.
  • Public sharing and import endpoints are unauthenticated public surfaces and must keep request size limits, rate limits, and SSRF protections in place.

There aren't any published security advisories