Blip is a single-branch project. Only the latest commit on main receives security fixes; there are
no maintained release branches and no backports to older tags.
Do not open a public issue for a security problem.
Report privately through GitHub's private security advisories on this repository. That is the intended channel — there is no separate security mailing address.
Include:
- A description of the issue and the component it affects.
- Steps to reproduce, ideally with a minimal request or client script.
- The impact you believe it has, and any configuration required to trigger it.
- The commit or version you tested against.
This is a personally maintained project, not a staffed product, so response times are best effort:
- An acknowledgement that the report was received.
- An assessment of whether the issue is reproducible and in scope.
- A fix on
mainfor confirmed issues, and credit in the advisory unless you ask otherwise.
If you do not hear back within a couple of weeks, feel free to follow up on the advisory thread.
In scope: anything reachable through the HTTP and WebSocket surface described in the
API reference — the origin check, the message size limit, the per-connection
rate limiter, the shutdown path, and the built-in test page at /test.
Out of scope, because they are documented properties of the design rather than defects:
- No authentication or authorization. Blip has none by design; enforce it in front of
/ws. See Security hardening. - No TLS. The server speaks plain HTTP and expects a reverse proxy to terminate TLS. See Deploying to production.
- No message persistence, no sender identity, and no delivery guarantee. See API reference.
/testbeing publicly reachable. It is a development aid with no disable flag; block it at the proxy in production.- Denial of service from a single-instance design. The hub lives in process memory and the process is not clustered.
- Security hardening — the controls and how to configure them
- Configuration reference — defaults and parsing rules