Skip to content

Security: beme08/gitvisual

SECURITY.md

Security

Supported versions

Version Supported
0.1.x ✅

Reporting a vulnerability

Please do not open a public issue for security problems. Use the repository's Security → Report a vulnerability form. If private vulnerability reporting is not available, contact the maintainer through their GitHub profile to request a private channel before sharing exploit details.

GitHub App threat model

What gitvis does

  • Requests no repository, organization, or account data permissions, then reads only the authorized account's publicly visible stars. The app does not require repository installation.
  • Never requests repository, organization, code, issue, workflow, administration, or write permissions.
  • Stores expiring user and refresh tokens only on the server, keyed by an opaque session id. Tokens never reach the browser, never enter localStorage, and are never logged.
  • Requires user-to-server token expiration and rotates a token if it approaches expiry.
  • Protects the authorization-code flow with a short-lived signed state cookie and PKCE (S256). The verifier stays in the HttpOnly cookie so an authorization in progress survives a server restart; it expires after 10 minutes.
  • Uses the configured APP_ORIGIN for the callback URL instead of trusting the incoming request host in production.
  • Keeps sessions in memory for one hour and caches fetched stars for 60 seconds. Both disappear when the server restarts.

What you should do as a user

  • Before authorizing, verify the GitHub App requests no repository, organization, or account data permissions.
  • To revoke gitvis's access to your account at any time, visit https://github.com/settings/applications and revoke the application.
  • Use HTTPS in production. The session cookie is marked Secure when APP_ORIGIN uses HTTPS.

What a self-hoster is responsible for

  • Keep GITHUB_APP_CLIENT_SECRET and SESSION_SECRET out of version control. Use the hosting provider's secret store.
  • Set APP_ORIGIN to the exact public HTTPS origin and configure the matching GitHub callback URL.
  • Set a strong SESSION_SECRET (32+ random characters). /api/health/ready refuses readiness without one.
  • If you deploy more than one instance, replace the in-memory session store in src/server/session.ts with a shared store (Redis, KV) so sessions work across instances. The v1 in-memory store does not.
  • Keep Node and dependencies up to date.

What gitvis does NOT do

  • It does not write to your GitHub account, ever.
  • It does not request permissions that would let it read private repositories, organizations, code, issues, or gists.
  • It does not track you, set cookies for analytics, or call third-party services beyond github.com/ghapi.

Current limitations

  • The public MVP is intentionally single-instance. Restarts invalidate sessions.
  • Refresh throttling is per session and in memory; it is not a distributed abuse-prevention system.
  • The content security policy currently permits inline scripts and styles required by the Astro-rendered page. It still blocks framing, plugins, and third-party script origins.

There aren't any published security advisories