Skip to content

Security: hestiaOS/hestiaos-mathdoc

Security

SECURITY.md

Security Policy

Scope

This repository contains the mathdoc library — a Markdown + LaTeX → PDF pipeline. It does not contain platform source code or any secrets, keys, or credentials.

Reporting a vulnerability

This repository is currently maintained as a private developer-preview repository. No public security reporting channel is active yet.

Before any public release, a verified private security reporting channel will be published and enabled where supported by the hosting platform.

When a reporting channel is available, please do not open public issues for undisclosed vulnerabilities; provide a clear description and reproduction steps where possible, and allow time for coordinated disclosure.

What not to include in reports

Do not include credentials, private keys, internal hostnames, or sensitive operational data in reports. Use neutral placeholders (e.g. node.example.internal).

Out of scope

  • Internal infrastructure, internal incident history, and non-public components are out of scope for this repository.

This policy intentionally contains no internal exposure reports or incident details.

There aren't any published security advisories