# Security Policy ## Supported versions Pocketdex is a rolling static web app — only the current `main` (and whatever is deployed from it) is supported. There are no maintenance branches. ## Reporting a vulnerability Please **don't** open a public issue for a security problem. Use GitHub's **private vulnerability reporting** (the *Report a vulnerability* button under the repository's *Security* tab). Include what you found, how to reproduce it, and the impact you think it has. You'll get an acknowledgement as soon as possible. Since Pocketdex has no backend and stores everything in the visitor's own browser, the realistic surface is: the service worker / caching, the save-file parser (`src/lib/savedex.js`) operating on untrusted binary input, and the JSON backup import. ## Known issues - **`npm audit` reports a moderate advisory for `esbuild` via Vite 5** (GHSA-67mh-4wv8-2f99). It affects the **local dev server only** — a malicious website could read responses from `npm run dev`. It is **not** present in the production build (`dist/`), which ships no dev server. Mitigation: don't expose the Vite dev server to untrusted networks. Upgrading past Vite 5 needs a newer Node baseline and is tracked as a follow-up.