Skip to content

Security: ch0sa/podforge-studio

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please open a GitHub issue with the security label, or contact the maintainers directly if the issue is sensitive. We aim to respond within a week.

Design posture

PodForge is a local-first application:

  • The server binds to 127.0.0.1 by default — it is not reachable from other machines.
  • No API keys or credentials are stored in the codebase; runtime state lives in data/ which is gitignored.
  • Episode transcripts are user data — they never leave the machine unless you configure an external writer backend yourself.

Known considerations

  • If you rebind the server to 0.0.0.0 for LAN/remote access, there is no authentication — anyone on that network can read your projects and trigger jobs. Put it behind a reverse proxy with auth, or use a VPN/Tailscale.
  • Downloading media via yt-dlp may be subject to the terms of service of the source platform; users are responsible for complying with them.

Scope

PodForge shells out to yt-dlp, ffmpeg and (optionally) opencode. Keep these updated; vulnerabilities in those tools affect this app too.

There aren't any published security advisories