Skip to content

Security: ArchAstro/clapper

Security

SECURITY.md

Security

Clapper executes the React/TypeScript project you ask it to render. Treat projects and their dependencies as executable code; do not run untrusted projects with access to credentials or sensitive files. The studio binds to loopback and is intended for local use, not exposure to the internet.

Please report suspected vulnerabilities privately through GitHub's Security → Report a vulnerability for ArchAstro/clapper when available. If private reporting is unavailable, contact the repository owner through their GitHub profile to arrange a private channel; do not put exploit details or credentials in a public issue.

Report the affected version, platform, reproduction steps and impact. The project currently supports its latest release; it has no formal security-response SLA.

There aren't any published security advisories