Goose Book is pre-1.0 software. Security fixes are shipped on the latest
main branch and tagged releases only.
Please report suspected vulnerabilities privately through GitHub Security Advisories when available. If that is unavailable, open a minimal issue that describes the affected surface without publishing exploit details.
Include:
- affected route or feature
- reproduction steps
- expected impact
- whether credentials, published stories, cloud sync, or public sharing are involved
- Goose Book uses BYOK for LLM providers. User API keys are stored only in the browser and are not included in cloud sync snapshots.
- Browser-side API key encryption protects against casual local inspection. It is not a defense against XSS, malicious extensions, or code running in the same origin.
- Supabase sync uses a publishable key. Row access must remain enforced by Supabase Auth and RLS policies.
- Public sharing and import endpoints are unauthenticated public surfaces and must keep request size limits, rate limits, and SSRF protections in place.