CalHub Creator 1.0.0
Security
The Figma document is untrusted input, and every exported package is validated again by the CalHub runtime.
Security boundary
- The plugin permits no network domain and has no account or authentication flow.
- Export is limited to the explicit current-page selection and its descendants.
- Runtime bindings, actions and data-access declarations come from a frozen allowlist shared with the CalHub package contract.
- Unsupported nodes, layouts and effects fail closed with a layer-specific repair message.
- Output uses canonical JSON, content-addressed assets and deterministic ZIP entries.
- CalHub independently validates manifest closure, digests, size limits and signatures at installation.
- Creator-provided authors, sources and license terms remain explicit; the plugin does not synthesize provenance.
Unsigned package status
Version 1.0.0 does not sign exported packages. CalHub refuses them in normal mode. Developer mode may install them only with a visible Unverified status until the signing and publishing flow exists.
Report a vulnerability
Email info@hyda.studio and identify the message as a CalHub Creator security report. Provide the smallest reproducible description.
Do not include private designs, .hyui packages, secrets, pairing credentials or household information in the initial report. Support will arrange a private channel if an attachment is necessary.