CalHub Creator 1.0.0

Security

The Figma document is untrusted input, and every exported package is validated again by the CalHub runtime.

Security boundary

Unsigned package status

Version 1.0.0 does not sign exported packages. CalHub refuses them in normal mode. Developer mode may install them only with a visible Unverified status until the signing and publishing flow exists.

Report a vulnerability

Email info@hyda.studio and identify the message as a CalHub Creator security report. Provide the smallest reproducible description.

Do not include private designs, .hyui packages, secrets, pairing credentials or household information in the initial report. Support will arrange a private channel if an attachment is necessary.