PixelDeck is pre-1.0. Security fixes are supported for the current main branch only.
Please report suspected security vulnerabilities through GitHub's private vulnerability reporting feature:
- Open the repository on GitHub.
- Click the Security tab (visible to all users).
- Click "Report a vulnerability".
- Fill in the private advisory form.
If the "Report a vulnerability" button is not visible, private reporting may not yet be enabled. In that case, contact the maintainers by opening a GitHub Discussion tagged [security] or via the contact listed in the repository profile. Do not create a public issue.
Do not open a public issue for security bugs. Public disclosure before a fix is ready puts all users at risk.
- Importing untrusted
ProjectJSON, which is a browser-side parsing trust boundary. - CLI export paths that execute Playwright against arbitrary project data.
- Vulnerabilities in Chromium itself. Please report those to Google.
- Google Fonts CDN availability, privacy, or delivery issues.
node_modulesvulnerabilities with no PixelDeck-specific impact or exploit path.
Maintainers aim to acknowledge reports within 72 hours and patch confirmed issues within 14 days.
There are no known past vulnerabilities.