Product Pass

Security

Report a vulnerability

Please email product-pass@moejay.dev with the subject “Product Pass security.” Do not open a public issue for an unpatched vulnerability.

Include affected versions, impact, reproduction steps, and a minimal proof of concept. Do not access data that is not yours or disrupt third-party services.

Architecture

Credential limitations

Credentials persist in browser storage.local, which is not a hardware-backed secret store. Anyone with sufficient access to your browser profile or device may be able to recover them. Use narrowly scoped GitHub tokens, protect your operating-system account, and disconnect credentials on shared devices.

Supported versions

Security fixes are provided for the latest published Product Pass version. Provider APIs and experimental integrations may change independently.