TinyJS App Studio is a GUI for the tinyjs runtime. Two surfaces, two flows — please read the scope before reporting.
This repo (the Studio) — the desktop app itself and everything it generates or writes:
src/main.js— the backend: CLI resolution, one-click installer, streaming, the per-project sidecar (.tinyjs-studio.json), and the finishing pass that patches generatedtinyjs.jsonfiles (chrome keys, inject, the badge gate exception).src/frontend/— the Studio UI and the CodeMirror vendor bundle.- Generated artifacts: the
inject.jsdrag strip, the config edits the Studio applies on top oftinyjs wrap.
Not this repo (the tinyjs runtime) — the security properties a wrapped
site actually faces: the per-origin capability gate, the RPC transport and its
session-token handshake, win.open confinement, subframe token gating,
storage isolation, the self-updater. Those live in
tarwin/tinyjsapp and are documented in
docs/THREAT-MODEL.md with links to the issues and
releases that shipped them. The Studio inherits them; it does not implement
them.
- Studio vulnerabilities — use GitHub private vulnerability reporting. Do not open a public issue.
- tinyjs runtime vulnerabilities (anything a wrapped or hosted page could abuse, bridge, launchers, updater, build chain) — report through the tinyjsapp security advisory flow so they reach the runtime maintainer directly. If you'd rather route it through us, open a private Studio advisory and we will forward it — but the fix and the disclosure happen upstream.
We aim to acknowledge reports within a few days and to coordinate disclosure with the reporter. No bounty program — credit in the release notes and the threat model instead.
- Don't open public GitHub issues for suspected vulnerabilities, here or upstream.
- Don't test against third-party wrapped apps or anyone else's machine — the adversarial suite runs against a local hostile page on your own machine only.
- Don't report as a Studio bug what is the runtime's documented posture (for
example, "a wrapped site can open native dialogs" — that is the
wrapperpreset, by design: see the threat model).
The Studio tracks the latest tinyjs release; security properties are those of
the runtime you drive it with (tinyjs --version). Security-relevant runtime
releases are called out in the
changelog — v0.45.0 and v0.46.0 are the most
recent hardening batches.