Skip to content

docs: document the SSRF guard requirement and decode bounds (v0.4.3) - #7

Merged
tannevaled merged 1 commit into
mainfrom
docs-security-v0.4.3
Oct 4, 2026
Merged

tannevaled merged 1 commit into
mainfrom
docs-security-v0.4.3

Conversation

@tannevaled

Copy link
Copy Markdown
Contributor

Mirrors the engine README's new security section: the library does not filter destinations, embedders need a dial guard (browserproxy has one), and raster decode refuses images over 25 megapixels.

🤖 Generated with Claude Code

…ne v0.4.3)

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@tannevaled
tannevaled merged commit 1129069 into main Oct 4, 2026
2 checks passed
@tannevaled
tannevaled deleted the docs-security-v0.4.3 branch October 4, 2026 17:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant