If you discover a security issue, please report it via GitHub Issues with a clear description. Avoid including sensitive details in public issues — you can email the maintainer directly if needed.
LingoPic is a macOS desktop application. Its security model relies on several layers:
API keys are stored in the macOS Keychain via /usr/bin/security, never written to disk in plaintext. Each provider's key is stored under a dedicated Keychain service name (com.jianglinwu.great-images-edit.api-key). The renderer process never sees the raw key — it only receives a hasKey: boolean indicator.
- contextIsolation: true — the renderer cannot access Node.js or Electron APIs directly
- nodeIntegration: false — no
require()in the renderer - sandbox: true — the renderer runs in a Chromium sandbox
- Preload script — uses
contextBridge.exposeInMainWorld()with a whitelist of IPC channels. Arbitrary IPC calls are rejected.
- window.open is denied via
setWindowOpenHandler(() => ({ action: 'deny' })) - will-navigate only allows navigation to the app's own entry point; all external URLs are blocked
The renderer enforces a Content-Security-Policy header:
default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline';
img-src 'self' data: blob:; font-src 'self' data:;
connect-src 'self' http://localhost:* https: ws://localhost:*;
media-src 'none'; object-src 'none'
- All HTTP requests go through Electron's
net.fetchwith configurable proxy support - Requests honor the system proxy or a user-configured manual proxy
- Timeout and retry logic prevents hanging connections
- Output files are written via atomic write (write to temp file → rename to target)
- Original files are never modified — the app reads source images but writes to a mirror directory
- The app only accesses the user-selected source folder and its mirror output directory
- Minimal dependency footprint: React 19, Electron 35, and font packages
- No native Node.js add-ons with C++ code
- All dependencies are pinned with
package-lock.json
| Version | Supported |
|---|---|
| 0.1.x | Yes |
Security issues will be acknowledged within 48 hours and patched as soon as practical. Fixes will be released as patch versions.