Rhombiverse is a small, single-developer project. There is no bug bounty and no dedicated security team — reports are handled directly by the maintainer.
Please report security issues privately, not as a public GitHub issue:
- Email: jamesbaker08@gmail.com
- Or: open a GitHub private security advisory on this repo.
Include what you found, how to reproduce it, and its impact if you can. You should get an acknowledgment within a few days.
Rhombiverse is a static, localStorage-only app: no accounts and no
backend. Client-side issues, such as XSS via an imported World file or
rendered text, are the main realistic surface.
Only the latest commit on master is supported. There are no
maintained release branches yet.