Security fixes are applied to the latest release on the main branch. This
project is currently alpha software.
Please do not open a public issue for vulnerabilities involving path escapes, arbitrary commands, credential exposure, unauthorized network access, or unsafe FreeShow mutations. Use GitHub's private vulnerability reporting for this repository. If that feature is unavailable, contact the repository owner privately through their GitHub profile.
Include the affected commit or release, reproduction steps, impact, and any suggested mitigation. Do not include live credentials or private church data.
FreeShow Web Tools has no application-level login. Its default listener is localhost-only. If you expose it on a Tailscale address, restrict access with tailnet ACLs. Never expose it directly to the public internet.