Security fixes are applied to the latest release line, currently v0.1.x.
Please use GitHub's private security advisory flow for the repository. Include reproduction steps, affected browsers, and the expected impact. Do not attach sensitive or proprietary image assets; use a minimal synthetic fixture.
TrueAlpha is a static browser application. It has no server, database, authentication, telemetry, or image-upload API. Source images are held in browser memory and are processed locally.
Reports intentionally exclude source image bytes. Object URLs are revoked when records are removed. Browser and static-host vulnerabilities remain outside the application's direct control, so users should run a current browser and deploy with HTTPS.