Security

Report vulnerabilities privately to clint@lgtm.systems; expect an acknowledgement within a week. Do not open public issues for exploitable defects.

Relevant guarantees the press intends to keep (breakage of any is a vulnerability): source archives never dereference symlinks and refuse secret-prone files; every generated output stays beneath the book root under a validated slug; CI outputs cannot be injected through book metadata; published sites carry only local, resolving references; three-part release tags are immutable across pipeline, action, and toolchain.

Repository security controls

The controls below form the supported baseline for this public project. The source-versioned ones are visible in the tree; the platform toggles are read back by a scheduled drift-check so none can be turned off unnoticed.

Canaries

Each control the press owns in the tree carries a known-bad fixture it rejects, paired with a clean case it passes (fail-before / pass-after); house law is that a checker is only real with a known-bad it rejects.

Accepted limitations