Vulnerability with hidden files on linux? Am I missing something?

I opened this issue on github:

I’m still investigating this behavior and I’ve not found a way to secure hidden files in the docs yet.

