Skip to content

Security: Riper21/MermaidGuard

Security

SECURITY.md

English | Русский

Security Policy

Scope

This project accepts source text and, when explicitly requested, sends a process description to a configured LLM provider. The core linter, Markdown handling, and offline synthesizer do not require network access or optional model packages.

Reporting

Report suspected vulnerabilities through the private security-advisory mechanism provided by the repository hosting the project. Do not include API keys, access tokens, private customer data, or unreleased source code in a report. If private reporting is unavailable, contact the maintainers through the channel documented by the hosting organization.

Do not open a public issue containing exploit details or sensitive data.

Handling guidance

  • Use a dedicated, least-privilege API key for LLM experiments and rotate it after use.
  • Review the selected provider's retention, training, and transport policies before sending descriptions.
  • Keep .env files out of version control. The repository ignores .env and its variants while retaining .env.example.
  • Treat generated Mermaid as untrusted text. A diagram source is not a safe HTML or script policy mechanism.
  • Review repairs before writing them into production documentation. The tool preserves uncertain input and reports failures, but users remain responsible for the final source.
  • Use --force only when replacing the selected output is intentional. The CLI rejects symbolic-link output paths and uses atomic replacement for regular files.
  • Keep input size limits enabled when processing files from untrusted locations.

Supported versions

The latest released version is the supported line. Security fixes are applied to the current release line unless a project release note states otherwise.

There aren't any published security advisories