Skip to content

Security: jianglin-wu/lingopic

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security issue, please report it via GitHub Issues with a clear description. Avoid including sensitive details in public issues — you can email the maintainer directly if needed.

Security Design

LingoPic is a macOS desktop application. Its security model relies on several layers:

API Key Storage

API keys are stored in the macOS Keychain via /usr/bin/security, never written to disk in plaintext. Each provider's key is stored under a dedicated Keychain service name (com.jianglinwu.great-images-edit.api-key). The renderer process never sees the raw key — it only receives a hasKey: boolean indicator.

Process Isolation

  • contextIsolation: true — the renderer cannot access Node.js or Electron APIs directly
  • nodeIntegration: false — no require() in the renderer
  • sandbox: true — the renderer runs in a Chromium sandbox
  • Preload script — uses contextBridge.exposeInMainWorld() with a whitelist of IPC channels. Arbitrary IPC calls are rejected.

Navigation Guards

  • window.open is denied via setWindowOpenHandler(() => ({ action: 'deny' }))
  • will-navigate only allows navigation to the app's own entry point; all external URLs are blocked

Content Security Policy

The renderer enforces a Content-Security-Policy header:

default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline';
img-src 'self' data: blob:; font-src 'self' data:;
connect-src 'self' http://localhost:* https: ws://localhost:*;
media-src 'none'; object-src 'none'

Network

  • All HTTP requests go through Electron's net.fetch with configurable proxy support
  • Requests honor the system proxy or a user-configured manual proxy
  • Timeout and retry logic prevents hanging connections

File System

  • Output files are written via atomic write (write to temp file → rename to target)
  • Original files are never modified — the app reads source images but writes to a mirror directory
  • The app only accesses the user-selected source folder and its mirror output directory

Dependencies

  • Minimal dependency footprint: React 19, Electron 35, and font packages
  • No native Node.js add-ons with C++ code
  • All dependencies are pinned with package-lock.json

Supported Versions

Version Supported
0.1.x Yes

Disclosure Timeline

Security issues will be acknowledged within 48 hours and patched as soon as practical. Fixes will be released as patch versions.

There aren't any published security advisories