OffPDF handles local documents, so security and privacy reports are taken seriously.
OffPDF is currently pre-release. Security fixes target the latest public source on the default branch until stable release channels exist.
Please do not post exploit details in a public issue.
Use GitHub Security Advisories once the public repository is available. Until then, contact the maintainer privately through offpdf.com or the maintainer profile.
Useful reports include:
- A short description of the issue.
- Steps to reproduce.
- A minimal sample file if the issue requires one and it can be shared safely.
- The operating system and OffPDF version or commit.
Security-sensitive areas include:
- File handling and path validation.
- Subprocess invocation.
- Temporary file cleanup.
- Packaged third-party binaries.
- Dependency vulnerabilities.
- Anything that could break the offline/no-upload privacy promise.