Only the latest commit on the main branch is actively maintained.
| Version | Supported |
|---|---|
| latest | ✅ |
| legacy | ❌ |
HAGURUMA is a client-side TypeScript visualizer with no backend, no authentication, and no data collection. While not safety-critical hardware, incorrect ratio math or misleading top-speed figures could lead to poor tuning decisions if used beyond its educational scope. Simulation results (0–100, quarter mile, grip limits) are estimates for comparison only — never use them for road or track decisions without independent verification.
If you find a calculation error, rendering bug, broken preset, or dependency vulnerability:
- Open a standard GitHub issue with exact reproduction steps.
- For security-related flaws (supply-chain, XSS vectors via share links / custom JSON import), open a Private Vulnerability Report.
- Share URL hash — packed
ctoken or verbose keys, decoded with range checks and unknown-key ignore; corrupt tokens are rejected, neverevalor inject raw hash content. - Custom car JSON import — validated field-by-field before
localStorage; reject non-finite numbers and oversized gear arrays. - Drivetrain INI import —
GEAR_n/FINAL/REVERSEparsed with strict ranges; unknown keys, sections and comments ignored. - Service worker — same-origin app shell plus capped stale-while-revalidate asset cache; report any cross-origin cache poisoning.
The Build APK workflow runs manually or automatically on published releases (attaching haguruma-<tag>.apk to the release). It produces a debug APK signed with the SDK debug key — sideloading and personal testing only, never a store release. A signed release would require a private keystore held outside this repository (never commit keystores, passwords, or signing configs). The Capacitor wrapper adds no extra permissions and runs the same local-only web app inside the system WebView: still no backend, no accounts, no data collection.