| Version | Supported |
|---|---|
| 1.x.x | ✅ |
If you discover a potential security vulnerability in BlockFall, please report it responsibly rather than opening a public issue.
- Security Contact: Contact the repository maintainers via GitHub Issues or Private Security Advisory.
- Report Details:
- Description of the issue and potential impact
- Step-by-step reproduction guide or proof-of-concept
- Affected browsers or runtime environments
We strive to acknowledge receipt of security reports within 48 hours and provide patches promptly.
- Storage Sanitization (
src/lib/storage.ts):localStorageis treated as untrusted user input.- All numerical properties (
highScore,bestLines,bestLevel,gamesPlayed,totalLines, and piece distribution maps) are validated withNumber.isFinite(), clamped to realistic non-negative integer ranges, and protected against integer overflow (max: 999_999_999). - Malformed, corrupt, or tampered payloads trigger an immediate safe fallback to default states without crashing.
- The codebase enforces strict TypeScript type bounds (
isolatedModules: true). - No dynamic code execution (
eval,new Function) is used anywhere in the application. - All screen reader announcements and status messages utilize validated text nodes (
aria-live="polite").
- HTTP and meta tag headers enforce:
X-Content-Type-Options: nosniffto prevent MIME-type sniffing.Referrer-Policy: strict-origin-when-cross-origin.- Proper viewport scaling controls (
viewport-fit=cover).
- BlockFall operates entirely offline on the client side.
- No user credentials, cookies, tokens, or personal identifiers are stored or transmitted.