繁體中文

Security, actually done

The full report (Traditional Chinese) is SECURITY_REPORT.md in the source. Summary below.

Audit results

pip-auditSuite venv (136 deps), subtitle-studio (36), 3 lock files: 0 known vulnerabilities
npm auditmockup-studio, invoice-pro, linkinbio-builder, _qa: 0 vulnerabilities
banditInitially 3 high / 4 medium / 48 low → fixed or justified inline; final 0
semgreppython / javascript / typescript / security-audit / secrets: 13 → 5 (all seller-only private keys, never in any public file or release)
gitleaksNo leaks in source; release archives scanned: 0 findings
pytest388 tests passing (incl. security tests)

Issues fixed (excerpt)

Honest limits

Client-side licence checks (Ed25519 included) can still be patched out by a determined user; stronger protection needs online activation.