Only the latest Bronom release receives security updates.
Please report vulnerabilities privately through a GitHub Security Advisory:
https://github.com/Netroforge/bronom/security/advisories/new
Do not open a public issue for a vulnerability. We aim to acknowledge reports within 48 hours and will coordinate disclosure and credit with the reporter.
Security reports are welcome for:
- MCP endpoint authentication or isolation bypasses
- Remote code execution through website content or the preload bridge
- Cross-tab or cross-client data exposure
- Unsafe permission handling
- Release pipeline or package integrity vulnerabilities
Regular defects and feature requests should use GitHub Issues.