Skip to content

Security: SamKuler/seat-cat

Security

SECURITY.md

Security Policy

Supported versions

Only the latest published SeatCat release receives security fixes.

Reporting a vulnerability

Please use the repository's private GitHub Security Advisory form. Do not open a public issue for vulnerabilities involving account data, unintended confirmation actions, permission escalation, or verification bypasses.

Include a minimal reproduction, affected version, browser, userscript manager, and expected security boundary. Remove credentials, Cookies, tokens, order numbers, and personal information.

Automation boundary

SeatCat may monitor a page, enter a showtime, select seats, and open the order-confirmation page according to the chosen level. It must pause every automated action while CAPTCHA or identity checks are detected and must never:

  • bypass authentication, CAPTCHA, risk controls, or rate limits;
  • read or transmit credentials, Cookies, or tokens;
  • execute remotely fetched code;
  • hide automated behavior from the user;
  • perform payment.

A change that weakens these boundaries is treated as a security-sensitive change and requires explicit review.

There aren't any published security advisories