| Version | Supported |
|---|---|
| 0.1.x | ✅ |
Please do not open a public issue for security problems. Use the repository's Security → Report a vulnerability form. If private vulnerability reporting is not available, contact the maintainer through their GitHub profile to request a private channel before sharing exploit details.
- Requests no repository, organization, or account data permissions, then reads only the authorized account's publicly visible stars. The app does not require repository installation.
- Never requests repository, organization, code, issue, workflow, administration, or write permissions.
- Stores expiring user and refresh tokens only on the server, keyed by an opaque session id. Tokens never reach the browser, never enter
localStorage, and are never logged. - Requires user-to-server token expiration and rotates a token if it approaches expiry.
- Protects the authorization-code flow with a short-lived signed
statecookie and PKCE (S256). The verifier stays in the HttpOnly cookie so an authorization in progress survives a server restart; it expires after 10 minutes. - Uses the configured
APP_ORIGINfor the callback URL instead of trusting the incoming request host in production. - Keeps sessions in memory for one hour and caches fetched stars for 60 seconds. Both disappear when the server restarts.
- Before authorizing, verify the GitHub App requests no repository, organization, or account data permissions.
- To revoke gitvis's access to your account at any time, visit https://github.com/settings/applications and revoke the application.
- Use HTTPS in production. The session cookie is marked
SecurewhenAPP_ORIGINuses HTTPS.
- Keep
GITHUB_APP_CLIENT_SECRETandSESSION_SECRETout of version control. Use the hosting provider's secret store. - Set
APP_ORIGINto the exact public HTTPS origin and configure the matching GitHub callback URL. - Set a strong
SESSION_SECRET(32+ random characters)./api/health/readyrefuses readiness without one. - If you deploy more than one instance, replace the in-memory session store in
src/server/session.tswith a shared store (Redis, KV) so sessions work across instances. The v1 in-memory store does not. - Keep Node and dependencies up to date.
- It does not write to your GitHub account, ever.
- It does not request permissions that would let it read private repositories, organizations, code, issues, or gists.
- It does not track you, set cookies for analytics, or call third-party services beyond
github.com/ghapi.
- The public MVP is intentionally single-instance. Restarts invalidate sessions.
- Refresh throttling is per session and in memory; it is not a distributed abuse-prevention system.
- The content security policy currently permits inline scripts and styles required by the Astro-rendered page. It still blocks framing, plugins, and third-party script origins.