If you discover a security vulnerability in kittyview, please report it through GitHub's private vulnerability reporting.
Do not open a public issue for security vulnerabilities.
Security-relevant areas of kittyview include:
- SVG rendering: SVGs are a rich format that can reference external files, embed scripts, and contain deeply nested structures. kittyview uses resvg (pure Rust, no scripting support) and defaults to blocking external file access (
--svg-resources none). - SVG foreignObject conversion: SVGs containing
<foreignObject>elements (common in mermaid-cli, draw.io, and D3.js output) are preprocessed before rendering. Embedded HTML is stripped to plain text and replaced with native SVG<text>elements. No HTML is interpreted or executed -- all markup is discarded and only text content is preserved. Entity decoding is limited to a fixed set of named entities and numeric character references. - Image decoding: Malformed images could trigger bugs in decoder libraries. All decoders are pure Rust (no C code).
- Terminal escape sequences: Malformed output could corrupt terminal state. kittyview buffers all protocol output before writing and validates terminal support before emitting.
Release binaries are built and attested with SLSA build provenance
by the release workflow. To verify that an asset came from the release it
claims to -- see Verifying downloads for why
--source-ref is what gives a passing check that meaning:
gh attestation verify kittyview-linux-amd64.tar.gz \
--repo gominimal/kittyview \
--source-ref refs/tags/v0.1.5 \
--deny-self-hosted-runnersSubstitute the tag of the release you downloaded.
Each release also includes the provenance bundle itself
(kittyview-provenance.intoto.jsonl) as an asset, so verification does not
have to query GitHub's attestation store. Fully offline verification also
needs a copy of the Sigstore trusted root, saved while still online:
gh attestation trusted-root > trusted_root.jsonlgh attestation verify kittyview-linux-amd64.tar.gz \
--repo gominimal/kittyview \
--source-ref refs/tags/v0.1.5 \
--deny-self-hosted-runners \
--bundle kittyview-provenance.intoto.jsonl \
--custom-trusted-root trusted_root.jsonl| Version | Supported |
|---|---|
| latest | Yes |